CVE-2026-37541: Openvehicles Open Vehicle Monitoring System Firmware
Critical severity, CVSS 10.0. EPSS: 1.1% chance of exploitation in the next 30 days.
Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is not properly validated, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted GVRET frames.
Affected products
- Openvehicles Open Vehicle Monitoring System Firmware: version 3.3.005 only
Published 2026-05-01. Last modified 2026-06-17.