Impact
KUNBUS piControl version 2.6.2 contains an out‑of‑bounds write in its process‑image management functionality. A local attacker who is authenticated with device configuration privileges can supply crafted configuration data and input to the piControl character device, allowing data to be written outside the bounds of the process‑image buffer and corrupt adjacent kernel memory. This kernel memory corruption can lead to system instability or complete denial of service.
Affected Systems
Devices running KUNBUS piControl 2.6.2 are affected. Other versions are not known to contain this flaw and are not listed as vulnerable.
Risk and Exploitability
The vulnerability scores a CVSS score of 7.3, indicating high severity. EPSS is not available and the issue is not listed in CISA’s KEV catalog. Exploitation requires local authenticated access to the device configuration interface and the piControl character device, so the attack surface is limited to insiders or compromised devices. If exploited, the attacker can corrupt kernel memory, which can crash the system or potentially allow further escalation. The lack of an available public patch increases the risk for impacted installations until a vendor fix is released.
OpenCVE Enrichment