CVE-2026-37541Disclosure(openvehicles / open_vehicle_monitoring_system)

LOWCVSS 10.0 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is not properly validated, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted GVRET frames.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • open_vehicle_monitoring_system
  • open_vehicle_monitoring_system_firmware

Threat summary

  • 10 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • General: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-05-12); latest day: 3
  • 10 total mentions across 4 days

Affected systems

Products
open_vehicle_monitoring_systemopen_vehicle_monitoring_system_firmware

2 versions affected across 2 products

Deep dive

Activity timeline10 mentions / 4d
01234Mentions · 2026-05-01: 2Mentions · 2026-05-02: 1Mentions · 2026-05-12: 4Mentions · 2026-05-29: 3Technical Details · 2026-05-01: 2Technical Details · 2026-05-12: 3Technical Details · 2026-05-29: 305-0105-0205-1205-29
Signal classification2 categories
Disclosure
770.0%
General
330.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-012
Disclosure2
2026-05-021
Disclosure1
2026-05-124
Disclosure1General3
2026-05-293
Disclosure3
Full discourse10 posts
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Open Vehicle Monitoring System (CVE-2026-37541) https://vuldb.com/vuln/360767

    Post summary

    A new vulnerability (CVE‑2026‑37541) for Open Vehicle Monitoring System has been disclosed, with the report noting an increased severity.

    0101083
    2.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On May 1, 2026, security researchers disclosed CVE-2026-37541, a critical-severity buffer overflow vulnerability in OVMS3 version 3.3.005. The flaw resides in the vehicle monitoring system's GVRET frame processing logic (canformatgvret.cpp) and carries a perfect CVSS 10.0…

    Post summary

    Researchers disclosed CVE‑2026‑37541 as a critical buffer overflow in OVMS3 3.3.005 with CVSS 10.0, but no PoC, exploit, or patch details were provided.

    1000055
    231 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Open Vehicle Monitoring System 3 (OVMS3) version 3.3.005 contains a CVSS 10.0 critical buffer overflow vulnerability in GVRET frame handling (CVE-2026-37541). Remote, unauthenticated attackers can exploit it without user interaction to achieve denial of service or…

    Post summary

    The post announces a critical buffer overflow vulnerability (CVE‑2026‑37541) in OVMS3’s GVRET frame handling, without mentioning PoC, exploit code, active exploitation, or remediation.

    1000072
    231 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Vehicle That Became the Weapon: CVE-2026-37541 OVMS3 Critical Buffer Overflow. Open Vehicle Monitoring System 3 OVMS3 version 3.3.005 contains a CVSS 10.0 critical buffer overflow vulnerability in GVRET frame handling CVE-2026-37541.

    Post summary

    A critical CVE-2026-37541 buffer overflow was identified in Open Vehicle Monitoring System 3 (v3.3.005), rated CVSS 10.0, but no PoC, exploit code, patch, or active exploitation details were mentioned.

    1000051
    231 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-37541 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post lists only the CVE identifier, CVSS score, severity, and advisory status, lacking details on exploitation, patches, or technical nature of the flaw.

    1000034
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CRITICAL: CVE-2026-37541 (CVSS 10) — multiple products. CVE: CVE-2026-37541 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE‑2026‑37541 as a critical vulnerability with CVSS 10, but it does not provide details on exploitability, patches, or active exploitation.

    1000027
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-37541 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005.

    Post summary

    A critical buffer overflow vulnerability (CVE-2026-37541) has been disclosed in Open Vehicle Monitoring System 3 (version 3.3.005) with a CVSS score of 10.

    1000031
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-37541 Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is not properly valid… https://www.cve.org/CVERecord?id=CVE-2026-37541

    Post summary

    The message announces a buffer overflow in OVMS3 3.3.005, giving technical details of the flaw but no evidence of exploitation or mitigation.

    00010162
    57.4K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-37541-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text consists solely of a link and hashtags, with no explicit information about the vulnerability, exploitation, or remediation.

    0000021
    210 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-37541 Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is not properly valid… https://www.cve.org/CVERecord?id=CVE-2026-37541 ----- Traducción: CVE-2026-37541 vul… http://infoflow.cloud`

    Post summary

    The post announces a buffer‑overflow CVE (CVE‑2026‑37541) in OVMS3, providing basic technical details but no PoC, exploit code, active exploitation, patches, or debunking.

    0000030
    75 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWopenvehiclesopen_vehicle_monitoring_system---
OSopenvehiclesopen_vehicle_monitoring_system_firmware3.3.005--

Explore more