CVE-2026-37541 - Vulnerability Analysis
CriticalCVSS: 10.0Last Updated: May 1, 2026
Open Vehicle Monitoring System 3 - Buffer Overflow
Published: May 1, 2026Updated: May 1, 2026Remote Exploitable
Overview
Open Vehicle Monitoring System 3 (OVMS3) 3.3.005 contains a buffer overflow caused by improper validation of the length field in GVRET binary data in canformat_gvret.cpp, letting remote attackers cause denial of service or execute arbitrary code via crafted GVRET frames.
Severity & Score
Severity: Critical
CVSS Score: 10.0
Impact
Remote attackers can cause denial of service or execute arbitrary code, potentially compromising the system.
Mitigation
Update to the latest version of Open Vehicle Monitoring System 3.
References
Related Resources
Details
- CVE ID
- CVE-2026-37541
- Severity
- Critical
- CVSS Score
- 10.0
- Type
- buffer_overflow
- Status
- new
CWE
- CWE-121
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H