Eclipse Foundation NetX Duo
18 known vulnerabilities in Eclipse Foundation NetX Duo, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-102717 CVSS 7.5 high MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash
- CVE-2026-102762 CVSS 8.2 high The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of…
- CVE-2026-102761 CVSS 9.3 critical NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the…
- CVE-2026-102760 CVSS 8.3 high When NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent on an active session is wiped after it has been handed to TCP…
- CVE-2026-102759 CVSS 6.3 medium NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a…
- CVE-2026-102758 CVSS 7.5 high The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the…
- CVE-2026-102728 CVSS 7.5 high Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is…
- CVE-2026-102727 CVSS 6.0 medium FTP Passive Data Connection Not Bound to the Authenticated Control Peer
- CVE-2026-102726 CVSS 6.0 medium Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read
- CVE-2026-102725 CVSS 6.0 medium Out-of-bounds Read from Unvalidated MSRP Attribute List Length
- CVE-2026-102724 CVSS 6.0 medium NULL Pointer Dereference When Evicting the Sole MSRP Attribute
- CVE-2026-102723 CVSS 6.0 medium NULL Pointer Dereference on MSRP Attribute Table Exhaustion
- CVE-2026-102722 CVSS 6.9 medium In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and…
- CVE-2026-102721 CVSS 6.9 medium A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path…
- CVE-2026-102718 CVSS 8.7 high hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer…
- CVE-2026-102714 CVSS 7.1 high `_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area…
- CVE-2026-102713 CVSS 8.8 high The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than four bytes (nxd_tftp_server.c:1037) and…
- CVE-2026-102712 CVSS 8.8 high On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against the…