VYPR
Critical severity9.1NVD Advisory· Published Jun 19, 2026· Updated Jun 25, 2026

CVE-2026-48137

CVE-2026-48137

Description

There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution.  Successful exploitation requires an attacker  to supply a specially crafted Moniker protobuf message.  This affects NI grpc-device 2.17.0 and prior versions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:ni:instrumentstudio:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:ni:instrumentstudio:*:*:*:*:*:*:*:*range: <=2025
    • cpe:2.3:a:ni:instrumentstudio:2026:q1:*:*:*:*:*:*
    • cpe:2.3:a:ni:instrumentstudio:2026:q2:*:*:*:*:*:*
  • cpe:2.3:a:ni:ni_grpc_device_server:*:*:*:*:*:*:*:*
    Range: <2.18.0
  • Ni/grpc-devicellm-fuzzy
    Range: <=2.17.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.