Remote Stack Buffer Overflow in Cesanta Mongoose MQTT Broker
CVE-2026-101003
6.9MEDIUM
What is CVE-2026-101003?
A vulnerability exists in Cesanta Mongoose MQTT Broker versions up to 7.21, specifically within the MQTT Broker component where a stack-based buffer overflow may be triggered through remote manipulation of the 'fn' function located in tutorials/mqtt/mqtt-server/main.c. This issue poses a significant risk as it could allow attackers to exploit the weakness remotely. It is crucial for users to upgrade to version 7.22, where this vulnerability has been addressed through patch a9df523f76f43a38bd53b4232b9cfd4c16869e71, to mitigate the security risks associated with this flaw.
Affected Version(s)
Mongoose 7.0
Mongoose 7.1
Mongoose 7.2
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
nemo2533 (VulDB User)
VulDB Vulnerability Moderation Team
