CVE-2026-14605
A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the library bsp/loongson/ls1cdev/libraries/ls1c_can.h of the component ls1c CAN Handler. Such manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Affected products
- Rt-Thread
- CVSS 4.0
- 8.5 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.1% (4th percentile)
- Weakness
- CWE-119, CWE-121
- NVD status
- Deferred
- Published
- 2026-07-03
CVE-2026-14605 at NVD
No indexed exploits for CVE-2026-14605 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-14605 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.