CVE-2026-102511
Last modified
CVE-2026-102511 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result's connection address was derived from the AmsNetId claimed in the response body rather than from the datagram's actual source address.
Description
Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result's connection address was derived from the AmsNetId claimed in the response body rather than from the datagram's actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices will open its ADS session, including any configured route credentials, to that host. Additionally, discovery listeners in both implementations can be disabled by a single malformed datagram: - In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported. - In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response. - The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response. Exploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items. This issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases. Users are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram's source address and logs a warning when the claimed AmsNetId disagrees with it.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Apache Software Foundation | Apache PLC4X | >= 0.11.0, < 1.0.0 |
| Apache Software Foundation | Apache PLC4X | >= 0.10.0, < 1.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-102511?
How severe is CVE-2026-102511?
How do I fix CVE-2026-102511?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-102505Imager versions before 1.037 for Perl overflow a heap buffer…6.3
- CVE-2026-102507Sliver C2 framework version 1.7.7 and earlier contains an un…5.7
- CVE-2026-102508Improper Verification of Cryptographic Signature and Imprope…9.2
- CVE-2026-102509Memory Allocation with Excessive Size Value, Allocation of R…8.7
- CVE-2026-10251A weakness has been identified in itsourcecode Online House …7.3
- CVE-2026-102510Integer Overflow, Improper Validation of Array Index, Uncont…8.7
- CVE-2026-102514Out-of-bounds Write (CWE-787) in the PEA archive extraction …8.4
- CVE-2026-10252A security vulnerability has been detected in itsourcecode O…7.3
- CVE-2026-102521The decoder in `readFromDataView` in lib0 before 0.2.119 can…8.6
- CVE-2026-10253A vulnerability was detected in itsourcecode Online House Re…7.3
- CVE-2026-10254A flaw has been found in SourceCodester Pet Grooming Managem…5.5
- CVE-2026-10255A vulnerability has been found in SourceCodester Pharmacy Sa…5.5
Are you affected by CVE-2026-102511?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
