CPATH-2026-0010 · General IoT

Swisslog Translogic TLP20 tcpTxThread stack overflow

Two or more co-dominant consequence paths connect the public security record to a provisional CRITICAL consequence band.

Candidate bandCRITICAL
Co-dominant pathsDevice-control safety + Device availability and recovery

These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

2 candidate paths · explicit source, inference, and assumption boundaries.

Safety · Co-dominant path

Device-control safety

Takeover can mis-route or halt transport, but no credible direct injury or dangerous high-energy actuation is demonstrated.

CRITICAL
  1. accessSource-backed

    Network-reachable without prior access

    Unauthenticated network packets to the TLP20 port.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    Chains across network to device to control-plane and is noted to chain to firmware persistence, crossing boundaries.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Operational safety effect

    Takeover can mis-route or halt transport, but no credible direct injury or dangerous high-energy actuation is demonstrated.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    Takeover can mis-route or halt transport, but no credible direct injury or dangerous high-energy actuation is demonstrated.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Recovery requires patching the vulnerable service and verifying affected stations before returning them to operation.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

Unauthenticated network packets to the TLP20 port.

Source-backedNVD
Execution complexityEC 3
Reproducible exploit workflow

Stack overflow with return-address control on a flat-memory RTOS with weak mitigations is a standard-to-advanced researcher workflow.

Source-backedNVD
ExposureEX 3
Execution effort limits exposure

The interface is broadly reachable, but the required technique keeps practical exposure below that reach.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Takeover can mis-route or halt transport, but no credible direct injury or dangerous high-energy actuation is demonstrated.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Remote code execution exposes operational and firmware-relevant state.

Model inference
AuthorityAT 3
Administrative or command authority

Code execution in the station controller can govern routing and pneumatic-tube behavior, but it does not provide a vendor firmware-signing key.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

Chains across network to device to control-plane and is noted to chain to firmware persistence, crossing boundaries.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same malformed message can be reused against affected stations that run the vulnerable Translogic service.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

Network-reachable, no per-device physical access needed.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Recovery requires patching the vulnerable service and verifying affected stations before returning them to operation.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Takeover can mis-route or halt transport, but no credible direct injury or dangerous high-energy actuation is demonstrated.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:2/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Recovery · Co-dominant path

Device availability and recovery

Loss of the station controller disrupts hospital logistics availability with no severe harm.

CRITICAL
  1. accessSource-backed

    Network-reachable without prior access

    The malformed network message can reach any affected station whose vulnerable service is exposed to the attacker.

    EvidenceNVD

  2. boundaryModel inference

    One cross-boundary bridge

    Chains less than full remote code execution, but still crosses network to device boundary.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Operational safety effect

    Loss of the station controller disrupts hospital logistics availability with no severe harm.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device availability and recovery

    Loss of the station controller disrupts hospital logistics availability with no severe harm.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch, reset, or reconfiguration

    Recovery requires patching or restarting affected stations and confirming that transport service has been restored.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

The malformed network message can reach any affected station whose vulnerable service is exposed to the attacker.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

A single malformed packet can crash the controller; the attacker does not need to turn the overflow into reliable code execution.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Loss of the station controller disrupts hospital logistics availability with no severe harm.

Model inference
Data / perceptionDP 1
Low-sensitivity state

Data and perception minimal (operational).

Model inference
AuthorityAT 2
Bounded function authority

Availability loss bounds the consequence to the device and component.

Model inference
Scale and recovery
ChainabilityCH 2
One cross-boundary bridge

Chains less than full remote code execution, but still crosses network to device boundary.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same vulnerable parser is present across affected station controllers, so the crash method can be repeated.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

Remotely reachable across stations.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

Recovery requires patching or restarting affected stations and confirming that transport service has been restored.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Loss of the station controller disrupts hospital logistics availability with no severe harm.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:4/EC:4/EX:4/PH:2/DP:1/AT:2/CH:2/SR:4/SX:4/OR:2/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the safety transition before acting on the band.

Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipDifferent consequence axis
Baseline confidencehigh
Scored2026-06-03
v3.1 · 9.8 CRITICALNVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Swisslog Translogic TLP20 tcpTxThread stack overflow at CRITICAL — the worst of 2 risk paths (safety). The dominant consequence is influence over a safety-relevant actuation.

Vulnerability

Swisslog Translogic TLP20 tcpTxThread stack overflow. Reported attack vector: Network.

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYCRITICAL

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:2/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:2/LS:PATCH_AVAILABLE

Exposure EX=3 (execution complexity-bound) · bands PH=HIGH · DP=HIGH · AT=CRITICAL → base CRITICAL · uplift fleet-reachable authority → assessed CRITICAL.

Unauthenticated network packets to the TLP20 port = RE:4. Stack overflow with return-address control on a flat-memory RTOS with weak mitigations is a standard-to-advanced researcher workflow = EC:3. RCE in the station controller control plane yields full code exec controlling the pneumatic-tube logistics device = AT:3 (control/command authority over the device, but not a signing root or OTA root, so not 4). Physical/safety: this is hospital pneumatic-tube logistics (specimens/meds transport); takeover can mis-route or halt transport, but no credible direct injury or dangerous high-energy actuation is demonstrated, so PH:2. RCE exposes operational/firmware-relevant state = DP:3. Chains across network->device->control-plane and is noted to chain to firmware persistence, crossing boundaries = CH:4, boundary_crossing true. Same parser across stations = SR:4 (portable exploit). Network-reachable, no per-device physical access needed = SX:4. Recovery requires patching to 7.2.5.7 across stations but not a signing-root rotation/recall = OR:3, recovery_needs_fleet_action false. Report-backed = EV:2. Not known exploited in the wild.

DEVICE_AVAILABILITYCRITICAL

CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:4/EC:4/EX:4/PH:2/DP:1/AT:2/CH:2/SR:4/SX:4/OR:2/EV:2/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=CRITICAL → base CRITICAL → assessed CRITICAL.

Pure DoS variant: same unauthenticated network reach to TLP20 port = RE:4. Crashing the controller via the overflow without needing reliable RCE is trivial/single-malformed-packet = EC:4. Loss of the station controller disrupts hospital logistics availability with no severe harm = PH:2. Availability loss bounds the consequence to the device/component = AT:2. Data/perception minimal (operational) = DP:1. Chains less than full RCE = CH:2, but still crosses network->device boundary = boundary_crossing true. Same parser everywhere = SR:4; remotely reachable across stations = SX:4. Recovery is service restart/patch, no fleet reprovision = OR:2. Report-backed = EV:2. Not exploited in the wild.

Published baseline

  • v3.1 9.8 CRITICAL — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — NVD

The published baseline above is retained for source review. Paths decomposes the consequence into authority, perception, safety, scale, and recoverability paths rather than using the baseline score as the primary registry frame.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0010 (“Swisslog Translogic TLP20 tcpTxThread stack overflow”), paths.cfse.ai/CPATH-2026-0010 (published 2026-06-03).