VYPR
advisoryPublished Sep 3, 2026· 1 source

Critical Buffer Overflow in Pyramid Solutions NetStaX EtherNet/IP Stack Exposes Industrial Control Systems

A severe stack-based buffer overflow vulnerability in Pyramid Solutions' NetStaX EtherNet/IP Stack could allow attackers to crash devices or achieve remote code execution.

CISA has issued a critical advisory detailing a stack-based buffer overflow vulnerability within the Pyramid Solutions NetStaX EtherNet/IP Stack, versions prior to v5.6.1. This flaw, identified as CVE-2026-78012, poses a significant risk to industrial control systems (ICS) and critical infrastructure worldwide.

The vulnerability arises from an issue where a specially crafted Class 3 explicit-message request can exceed the application-side receive buffer without triggering any error or warning. This lack of validation allows an attacker to potentially corrupt memory, leading to device crashes or, more critically, enabling remote code execution. The absence of a CIP error message means that the affected device might not indicate that the request could not be processed, making detection more challenging.

This vulnerability affects a wide range of Pyramid Solutions' EtherNet/IP products, including various DLL and Development Kits for both adapters and scanners, with and without CIP Security. The affected products include the EtherNet/IP Adapter DLL Kit (EIPA), EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE), EtherNet/IP Adapter Development Kit (EADK), EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE), EtherNet/IP Scanner DLL Kit (EIPS), EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE), EtherNet/IP Scanner Development Kit (ESDK), and EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE), all prior to version 5.6.1.

The potential impact of exploiting CVE-2026-78012 is severe, with CVSS v3.1 scoring it at a critical 9.8. Successful exploitation could lead to memory corruption, device crashes, and a potential remote attack vector. Given that EtherNet/IP is a widely used industrial communication protocol, the affected systems are prevalent in critical manufacturing, energy, and water and wastewater sectors globally, making the potential for widespread disruption significant.

Pyramid Solutions has addressed this vulnerability in NetStaX v5.6.1 by implementing multiple layers of protection. These include a compile-time assertion, a runtime payload-size check, and enhanced documentation regarding the relationships between packet and buffer-size constants. Users are strongly advised to update to version 5.6.1 or later to mitigate the risks associated with this flaw.

CISA recommends that organizations minimize network exposure for all control system devices and systems, ensuring they are not accessible from the internet. Isolating control system networks behind firewalls and segmenting them from business networks is crucial. When remote access is necessary, secure methods like VPNs should be employed, with the understanding that VPNs themselves require regular updates and secure configurations.

While there are no known public exploits specifically targeting this vulnerability at this time, the critical nature of the flaw and its potential impact on industrial operations warrant immediate attention. Organizations operating critical infrastructure should prioritize updating their Pyramid Solutions NetStaX EtherNet/IP Stack installations to the latest version to prevent potential exploitation.

This advisory underscores the ongoing security challenges within the Industrial Internet of Things (IIoT) and the importance of robust security practices for operational technology (OT) environments. As industrial systems become more interconnected, vulnerabilities in communication protocols can have far-reaching consequences.

Synthesized by Vypr AI