EIP-2026-116873

PRE-CVE

BACnet OPC Client - Local Buffer Overflow (Metasploit) (2)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-116873. PoCs published by Metasploit.

AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in SCADA Engine BACnet OPC Client v1.0.24 by crafting a malicious CSV file that triggers arbitrary code execution when parsed. The exploit leverages a return address overwrite with a payload encoded to avoid bad characters.

Description

BACnet OPC Client - Local Buffer Overflow (Metasploit) (2)

Exploits (1)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/16668

This Metasploit module exploits a stack buffer overflow in SCADA Engine BACnet OPC Client v1.0.24 by crafting a malicious CSV file that triggers arbitrary code execution when parsed. The exploit leverages a return address overwrite with a payload encoded to avoid bad characters.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SCADA Engine BACnet OPC Client v1.0.24
No auth needed
Prerequisites: Victim must open the malicious CSV file in the vulnerable BACnet OPC Client
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026