Buffer Overflow Vulnerability in TFTP Server from ThreadX
CVE-2026-102713
What is CVE-2026-102713?
The TFTP server in ThreadX contains a critical vulnerability that allows it to accept DATA datagrams of arbitrary sizes without proper validation, leading to potential memory disclosures and server denial of service. The lack of upper bounds checks enables an attacker to craft specially sized datagrams that can overwrite memory, causing an overflow and disclosing sensitive information from the server's memory. Additionally, the TFTP server can become unresponsive, suspending its thread indefinitely if the datagram exceeds the pool capacity, blocking service to legitimate client requests. Mitigation strategies involve implementing strict size checks for incoming packets and adjusting server settings to prevent indefinite suspension during packet handling.
Affected Version(s)
NetX Duo 0 <= 6.5.1.202602
