OpENer EtherNet/IP stack: five unauthenticated denial-of-service flaws (CVE-2026-75345 to 75349, each CVSS 7.5) in packet parsing, including a cross-protocol stack use-after-return; affects v2.3 and master up to commit 76b95cf, issues still open with no fix
Five CVEs published on 9 October 2026 cover OpENer, the open-source EtherNet/IP adapter stack maintained by the EIPStackGroup on GitHub and used as a base for industrial devices that speak the CIP protocol. All five affect OpENer v2.3 and the master branch up to commit 76b95cf and are rated 7.5 under CVSS 3.1 (network, no authentication, availability impact): CVE-2026-75347 is a stale-pointer bug in Common Packet Format (CPF) handling, where a UDP I/O packet leaves a pointer to a finished stack frame that a later TCP SendUnitData packet reuses (GitHub issue #575, opened 28 May 2026, says it reproduces against the unmodified POSIX server); CVE-2026-75348 is an out-of-bounds read in the TCP SendRRData CPF parser (issue #573); CVE-2026-75346 is an out-of-bounds read in the CIP SetAttributeList service (issue #572); CVE-2026-75349 is an out-of-bounds read in Connection Manager request parsing (issue #577); and CVE-2026-75345 is an out-of-bounds read in the unconnected explicit messaging path. Each lets a remote attacker crash the stack. The issues were still open when the CVEs were published and the repository's latest commits are dependency bumps, so no fixed release exists. The CVE records were assigned by MITRE, not a vendor, and no product makers have yet said which devices embed affected OpENer code. No exploitation reported. Primary: CVE records and OpENer GitHub issues.
- Product
- EIPStackGroup OpENer open-source EtherNet/IP (CIP) adapter stack
- Versions
- OpENer v2.3 and master up to and including commit 76b95cf
- CVSS
- (CVSS 3.1, each of the five CVEs; MITRE CNA)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - Exploited in Australia?
- unknown
- Patch to
- No fix yet: watch the OpENer issues for patches and ask device vendors whether their EtherNet/IP adapters embed OpENer. Meanwhile restrict EtherNet/IP (TCP/UDP 44818 and UDP 2222) to known controllers and engineering stations, keep OT networks segmented from IT and the internet, and monitor for unexpected adapter restarts.
Primary: OpENer GitHub issue #575 — cross-protocol stale CPF data_item reuse causes stack-use-after-return (CVE-2026-75347) · Vendor: EIPStackGroup OpENer — EtherNet/IP stack repository (issues #572, #573, #575, #577) · CVE: CVE-2026-75345, CVE-2026-75347, CVE-2026-75348, CVE-2026-75346, CVE-2026-75349 · NVD — CVE-2026-75347 (OpENer CPF expired pointer dereference, 9 Oct 2026)
