[Japanese]

JVNDB-2026-033631

Panasonic Industry MINAS A5/A6 USB device drivers for Windows vulnerable to buffer overflow

Overview

MINAS A5/A6 USB device drivers for Windows provided by Panasonic Industry Co., Ltd. contain the following vulnerability.
  • Classic Buffer Overflow (CWE-120) - CVE-2026-16726
Luca Borzacchiello of Nozomi Networks reported the issue directly to Panasonic.
Panasonic reported this issue to JPCERT/CC to notify users of its solution through JVN.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 5.5 (Medium) [Other]
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: None
  • Integrity Impact: None
  • Availability Impact: High
Affected Products

The affected device drivers are contained in the following software.

Panasonic Industry Co., Ltd.
  • GM Programmer versions 2.2.1.0 and earlier
  • PANATERM v6 versions 6.0.13.0 and earlier
  • PANATERM for Multi versions 6.2.3.1 and earlier
  • PANATERM v7 versions 7.5.0.0 and earlier
  • RTEX LogReader versions 15.0.0.591 and earlier

Impact

If the user is directed to connect some malicious USB device to the Windows PC, the USB device driver may crash and result in the DoS (Denial-of-Service) condition on Windows.
Solution

[Update the Software]
Update the software to the latest version according to the information provided by the developer.
Vendor Information

Panasonic Industry Co., Ltd.
CWE (What is CWE?)

  1. Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')(CWE-120) [Other]
CVE (What is CVE?)

  1. CVE-2026-16726
References

  1. JVN : JVNVU#99837984
Revision History

  • [2026/09/16]
      Web page was published