CODESYS Control - Out-of-bounds Write
[Advisory2026-10_VDE-2026-057] The CmpWebServer component in the CODESYS Control Runtime allows users to create browser-based visualizations for monitoring and controlling industrial processes. Due to improper bounds checking, a specially crafted HTTP request from an unauthenticated remote attacker may lead to a size-limited out-of-bounds write, causing a denial of service of the affected device. The CODESYS Control runtime system is only affected if the web server is active, which by default…
EPSS 0.00 CVE-2026-8047 CODESYS DE