CVE-2026-48137
EUVD-2026-3801219.06.2026, 14:16
There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution. Successful exploitation requires an attacker to supply a specially crafted Moniker protobuf message. This affects NI grpc-device 2.17.0 and prior versions.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ni | instrumentstudio | 𝑥 ≤ 2025 |
| ni | ni_grpc_device_server | 𝑥 < 2.18.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration