Critical severity9.8NVD Advisory· Published Apr 14, 2022· Updated Jun 17, 2026
CVE-2022-26507
CVE-2022-26507
Description
A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:schneider-electric:ecostruxure_control_expert:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:schneider-electric:ecostruxure_control_expert:*:*:*:*:*:*:*:*range: <15.1
- cpe:2.3:a:schneider-electric:ecostruxure_control_expert:15.1:-:*:*:*:*:*:*
- cpe:2.3:a:schneider-electric:ecostruxure_process_expert:*:*:*:*:*:*:*:*Range: <2021
- cpe:2.3:a:schneider-electric:remoteconnect:-:*:*:*:*:*:*:*
- AT&T Labs/Xmilldescription
Patches
Vulnerability mechanics
References
2- claroty.comnvdNot ApplicableThird Party Advisory
- download.schneider-electric.com/filesnvdMitigationRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.