TopVuln

High-risk vulnerability digests

CVE-2026-37541

  • CRITICAL

cve@mitre.org

Details

CVSS v3
10.0
NVD published
2026-05-01 17:16:24
EPSS
0.2% probability · 44.3th percentile — 2026-05-12
Affected versions
Open Vehicle Monitoring System 3 (OVMS3) 3.3.005
Summary
This vulnerability occurs due to missing validation of the length field in GVRET binary data processed by OVMS3. A remote attacker can send a crafted GVRET frame to trigger a buffer overflow. Successful exploitation may lead to denial of service or remote arbitrary code execution on affected systems.
Remediation
Apply the latest official security patch from the Open Vehicle Monitoring System project. Organizations running affected versions should restrict untrusted network access to the OVMS3 service until remediation is completed.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.