Impact
A vulnerability exists in the modbusgwd service of Teltonika Networks RUTOS devices. Improper handling of incoming Modbus TCP request data can cause a heap-based buffer overflow. When exploited, this flaw can crash the modbusgwd daemon, denying service to legitimate users. The flaw does not provide a path to code execution or data disclosure, but it does allow an attacker to disrupt network device operation.
Affected Systems
Teltonika Networks RUTOS firmware versions prior to 7.24.2 are affected. The vulnerability is tied to the modbusgwd component, which processes Modbus TCP traffic. Any device running an unsupported RUTOS version that exposes the Modbus service to external networks is within scope.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known large-scale exploitation yet. Attackers can trigger the overflow by sending crafted Modbus TCP requests from any network that can reach the device, without needing authentication. While the impact is limited to service denial, the ease of exploitation poses a risk to operational continuity for network infrastructure relying on the affected device.
OpenCVE Enrichment