CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-48137

Critical · CVSS 9.1

NI grpc-device — Untrusted pointer dereference RCE (CWE-822) via crafted protobuf message

CVSS
9.1
nvd
EPSS
0.50%
39th pct
KEV
No
Class
other
CWE-822

Description

There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution.  Successful exploitation requires an attacker  to supply a specially crafted Moniker protobuf message.  This affects NI grpc-device 2.17.0 and prior versions.

Search profile — drives PoC discovery

Symbols grpc-devicesideband streaming APIMonikerprotobufMonikerReadArrayI16MonikerWriteArrayI16BeginSidebandStreamingSidebandStreamingRequestSidebandStreamingResponseInitiateSidebandStream
Keywords CVE-2026-48137GHSA-ww59-ghm9-mm63NI grpc-devicegrpc-device sidebandMoniker protobufuntrusted pointer dereferencegrpc-device RCENI grpc-device exploitgrpc-device PoCCWE-822 grpc-device
Versions: <= 2.17.0

References

Status: enriched · ingested 2026-06-25T18:00:38.000Z · profiled 2026-07-01T18:30:14.000Z