VYPR

C-Open

by RT Labs AB

CVEs (2)

  • CVE-2026-82358MedOct 1, 2026
    risk 0.42cvss 6.5epss —

    RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/co_sdo_server.c' that fails to properly validate write permissions when processing download-segment frames. An unauthenticated attacker on the CAN bus can…

  • CVE-2026-82357MedOct 1, 2026
    risk 0.42cvss 6.5epss —

    RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user application may not have all required subindexes for object 0x1018. An unauthenticated, remote attacker with access to the CAN bus,…