CVE-2026-41502 | bacnet-stack BACnet Stack up to 1.4.2 ReadPropertyMultiple Service src/bacnet/rpm.c rpm_decode_object_id out-of-bounds (GHSA-7545-3fpx-4xw3 / EUVD-2026-25624)
A vulnerability classified as problematic was found in bacnet-stack BACnet Stack up to 1.4.2. Impacted is the function rpm_decode_object_id of the file src/bacnet/rpm.c of the component ReadPropertyMultiple Service. The manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2026-41502. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.