Back

CRITICAL

Stack-based Buffer Overflow in MZ Automation libIEC61850

Published Jul 23, 2026

Description

The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.

Affected products

Remediation

Vendor solution

MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850. https://github.com/mz-automation/libiec61850

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Jul 23, 2026
Updated Jul 24, 2026
Reserved Jun 9, 2026
CISA Vulnrichment
Updated Jul 24, 2026
NVD
Status Deferred
Modified Jul 30, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner icscert
Published Jul 23, 2026
Updated Jul 24, 2026
Exploited since n/a
EUVD-2026-48430