CVE-2026-37541

CRITICAL

Open Vehicle Monitoring System 3 3.3.005 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is not properly validated, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted GVRET frames.

Scores

CVSS v3 10.0
EPSS 0.0019
EPSS Percentile 41.1%
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

Status published
Published May 01, 2026
Tracked Since May 01, 2026