{"id":"CVE-2026-13214","summary":"Stack buffer overflow in OCPP GetConfiguration key parsing","details":"The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request from the central system, the handler copied the attacker-controlled JSON \"key\" string into the caller's fixed 50-byte stack buffer (skey[CISTR50], declared in subsys/net/lib/ocpp/ocpp.c) using an unbounded strcpy(). The parsed key value points directly into the receive buffer, so its length is bounded only by the message size (CONFIG_OCPP_RECV_BUFFER_SIZE, default 2048).\n\nThe GetConfiguration message is delivered over the WebSocket connection that the charge point opens to its configured central system. The reader thread ocpp_wsreader() reads the message into ui-\u003erecv_buf and dispatches it to parse_getconfig_msg() via the PDU function table. An attacker who controls the central system endpoint, or a man-in-the-middle on an unencrypted connection, can send a GetConfiguration request whose \"key\" field exceeds 50 bytes and overflow the reader thread's stack with attacker-chosen bytes.\n\nThe consequence is a remotely triggerable stack smash on the OCPP reader thread: at minimum a denial of service, and plausibly remote code execution depending on build-time hardening such as stack canaries and MPU configuration. The fix replaces the strcpy() with a bounded strncpy(key, payload.key[0], CISTR50 - 1) followed by explicit NUL termination, matching the bounded copies already used by the sibling handlers.","aliases":["GHSA-fqhf-6v24-4px2"],"modified":"2026-08-28T14:32:56.782690Z","published":"2026-08-25T04:37:20.629Z","database_specific":{"cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/13xxx/CVE-2026-13214.json","cna_assigner":"zephyr"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/13xxx/CVE-2026-13214.json"},{"type":"ADVISORY","url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fqhf-6v24-4px2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13214"},{"type":"FIX","url":"https://github.com/zephyrproject-rtos/zephyr/commit/afbf880b04188ae53451a0ade4ac62b654fdff34"},{"type":"PACKAGE","url":"https://github.com/zephyrproject-rtos/zephyr"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zephyrproject-rtos/zephyr","events":[{"introduced":"3568e1b6d5cdd51a6b964a2a1d6d29200fea2056"},{"fixed":"afbf880b04188ae53451a0ade4ac62b654fdff34"}],"database_specific":{"extracted_events":[{"introduced":"4.3.0"},{"fixed":"4.4.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v4.4.0","v4.4.0-rc3","v4.4.0-rc2","v4.4.0-rc1","v4.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-13214.json","vanir_signatures_modified":"2026-08-28T14:32:56Z","vanir_signatures":[{"id":"CVE-2026-13214-705ee633","signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/afbf880b04188ae53451a0ade4ac62b654fdff34","target":{"file":"subsys/net/lib/ocpp/ocpp_j.c","function":"parse_getconfig_msg"},"deprecated":false,"digest":{"function_hash":"186468756718606674659820147338427050198","length":424}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/afbf880b04188ae53451a0ade4ac62b654fdff34","target":{"file":"subsys/net/lib/ocpp/ocpp_j.c"},"deprecated":false,"digest":{"line_hashes":["170653415534705811885530058114443768547","220914679847034149204095315487465218633","177240728858952022581174414645664249970","71044681768474169245967749522313398407"],"threshold":0.9},"id":"CVE-2026-13214-badc81f6"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}