Home

Description

Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is not properly validated, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted GVRET frames.

PUBLISHED Reserved 2026-04-06 | Published 2026-05-01 | Updated 2026-05-07 | Assigner mitre




CRITICAL: 10.0CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N

References

github.com/openvehicles/Open-Vehicle-Monitoring-System-3

gist.github.com/sgInnora/f4ac66faeefe07a653ceeb3f58cdc381

github.com/...s/Open-Vehicle-Monitoring-System-3/issues/1393

cve.org (CVE-2026-37541)

nvd.nist.gov (CVE-2026-37541)

Download JSON