CVE-2026-42469: Openvehicles Open Vehicle Monitoring System Firmware

High severity, CVSS 8.6. EPSS: 0.6% chance of exploitation in the next 30 days.

Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_canswitch.cpp the parser does not properly validate a CANswitch DLC value, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted CANswitch frames.

Affected products

  • Openvehicles Open Vehicle Monitoring System Firmware: version 3.3.005 only

Published 2026-05-01. Last modified 2026-06-17.