BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability has been discovered in BACnet Stack's file writing functionality where there is no validation of user-provided file paths, allowing attackers to write files to arbitrary directories. This affects apps/readfile/main.c and ports/posix/bacfile-posix.c. This vulnerability is fixed in 1.5.0.rc3.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bacnetstack
Bacnetstack bacnet Stack |
|
| Vendors & Products |
Bacnetstack
Bacnetstack bacnet Stack |
Fri, 13 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Feb 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability has been discovered in BACnet Stack's file writing functionality where there is no validation of user-provided file paths, allowing attackers to write files to arbitrary directories. This affects apps/readfile/main.c and ports/posix/bacfile-posix.c. This vulnerability is fixed in 1.5.0.rc3. | |
| Title | BACnet Stack Improperly Limits Pathnames to a Restricted Directory | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-13T18:53:59.648Z
Reserved: 2026-01-05T17:24:36.928Z
Link: CVE-2026-21878
Updated: 2026-02-13T18:53:52.251Z
Status : Awaiting Analysis
Published: 2026-02-13T19:17:28.650
Modified: 2026-02-13T21:43:11.137
Link: CVE-2026-21878
No data.
OpenCVE Enrichment
Updated: 2026-02-13T21:28:30Z