Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bacnetstack

First CVE: Feb 29, 2024Active for: 2 yearsTotal CVEs: 9

Bacnetstack is a narrowly scoped but strategically important building-automation protocol library that appears across critical infrastructure and HVAC control systems, presenting a concentrated attack surface in industrial and facilities environments. Vulnerabilities affecting the vendor skew toward serious outcomes, clustering around memory-safety and input-handling weaknesses such as out-of-bounds reads, off-by-one errors, buffer over-reads, and path-traversal flaws that are characteristic of protocol parsing in embedded control contexts. Defenders should prioritize inventory and isolation of systems running this library, as the building-automation sector's operational-continuity constraints complicate rapid patching; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bacnetstack over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 29, 2024
2 years ago
Most Recent CVE
Apr 24, 2026
91 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-41475CRITICAL
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-stack's WritePropertyMultiple serv
Apr 24, 20269.133NONO
CVE-2026-41503HIGH
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-stack's ReadPropertyMultiple servi
Apr 24, 20267.528NONO
CVE-2026-41502HIGH
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an off-by-one out-of-bounds read vulnerability in bacnet-stack's ReadPropertyMul
Apr 24, 20267.528NONO
CVE-2026-21878HIGH
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability has been discovered in BACnet Stack's file writing functiona
Feb 13, 20267.525NONO
CVE-2025-66624HIGH
BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communications services. Prior to 1.5.0.rc2, The npdu_is_expected_repl
Dec 5, 20257.525NONO
CVE-2026-26264HIGH
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0rc4 and 1.4.3rc2, a malformed WriteProperty request can trigger a length underflow
Feb 13, 20268.124NONO
CVE-2023-51773CRITICAL
BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c.
Feb 29, 20249.124NONO
CVE-2026-21870MEDIUM
BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communications services. In 1.4.2, 1.5.0.rc2, and earlier, an off-by-o
Feb 13, 20265.521NONO
CVE-2026-40279LOW
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, decode_signed32() in src/bacnet/bacint.c reconstructs a 32-bit signed integer fr
Apr 21, 20263.716NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
11%
11%
56%
22%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (11.1%)
Network8 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None8 (88.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bacnetstack.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bacnetstack — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bacnetstack's Products

View all 2 CNAs →

Top CWEs