CVE-2026-21870 is an off-by-one stack-based buffer overflow vulnerability affecting versions 1.4.2, 1.5.0.rc2, and earlier of the BACnet Protocol Stack library. This flaw, specifically in the ubasic interpreter's tokenizer_string function, can cause a denial of service (SIGABRT crash) when processing overly long string literals due to incorrect null termination. Rated Medium severity with a CVSS score of 5.5, the vulnerability requires local access and user interaction (UI:R) to trigger, with the primary impact being high availability loss. There is no confidentiality or integrity impact. Currently, there is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. The CVE also shows minimal community discussion or media coverage, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4.2CPE matchmatch criteria | cpe:2.3:a:bacnetstack:bacnet_stack:*:*:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:bacnetstack:bacnet_stack:1.5.0:rc1:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:bacnetstack:bacnet_stack:1.5.0:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.