A vulnerability identified as critical has been detected in debevv nanoMODBUS up to 1.23.0. This affects the function recv_read_device_identification_res of the file nanomodbus.c of the component Client Receive Logic. This manipulation of the argument buffers_length causes out-of-bounds write.

This vulnerability is registered as CVE-2026-71255. Remote exploitation of the attack is possible. No exploit is available.