CVE-2026-56111
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
24/06/2026
Last modified:
14/07/2026
Description
Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-bounds write vulnerability in the M421 G-code handler that allows attackers to corrupt firmware memory by supplying out-of-range X and Y grid indices. Attackers can send a single crafted G-code command via USB serial, network interface, or malicious gcode file to write an attacker-controlled 32-bit float value past the z_values array bounds, corrupting adjacent firmware variables and causing denial of service or firmware state corruption.
Impact
Base Score 4.0
8.30
Severity 4.0
HIGH
Base Score 3.x
9.10
Severity 3.x
CRITICAL



