CVE-2026-102762

The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool and stops all inbound network traffic on the device until it is rebooted.

  • Published Sep 29, 2026
  • CVSS 8.2 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-102762 at the National Vulnerability Database