CVE-2026-61893

A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.

Credits

arun babu puthuparambil of Central Power Research Institute, Bengaluru, India reported this vulnerability to CISA.

References