CVE-2026-50032

A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.

Credits

Abhinav Agarwal reported this vulnerability to CISA

References