Buffer Overflow Vulnerability in TFTP Server from ThreadX
CVE-2026-102713

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102713?

The TFTP server in ThreadX contains a critical vulnerability that allows it to accept DATA datagrams of arbitrary sizes without proper validation, leading to potential memory disclosures and server denial of service. The lack of upper bounds checks enables an attacker to craft specially sized datagrams that can overwrite memory, causing an overflow and disclosing sensitive information from the server's memory. Additionally, the TFTP server can become unresponsive, suspending its thread indefinitely if the datagram exceeds the pool capacity, blocking service to legitimate client requests. Mitigation strategies involve implementing strict size checks for incoming packets and adjusting server settings to prevent indefinite suspension during packet handling.

Affected Version(s)

NetX Duo 0 <= 6.5.1.202602

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

L0stHeart
.