CVE-2026-48138 Details
Description
There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may result in a denial of service. Successful exploitation requires an attacker to supply a specially crafted write request. This affects NI grpc-device 2.17.0 and prior versions.
A denial-of-service vulnerability has been identified in the NI gRPC Device Streaming API, present in versions through 2.17.0. The issue arises from an out-of-bounds read caused by a missing bounds check, which could be exploited by an attacker sending a specially crafted write request.
Users are advised to upgrade to NI gRPC Device Server version 2.18.0 or later. This update can be obtained through the NI Update Service, which is a Windows utility that delivers updates for NI software and drivers, including security patches.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ni instrumentstudio | <= 2025 2026 q1 2026 q2 |
CPE
Remediation
| |
| ni ni grpc device server | < 2.18.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | Initial Analysis | [email protected] |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | New CVE Received | [email protected] |