IcmpV6 Option Validation Flaw in NetX Duo by Eclipse
CVE-2026-102714

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102714?

The vulnerability in Eclipse's NetX Duo arises from an improper validation in the _nx_icmpv6_validate_options() function, which fails to examine potential trailing bytes during option processing. This oversight can lead to potential denial of service as the system enters a loop without yielding, freezing operations until a watchdog reset occurs. Additionally, the mismanagement of unsigned counters may lead to underflows, causing the process to access memory beyond allocated buffers. The outcome may compromise system stability and allow for unwanted memory manipulation. The flaw primarily affects how ICMPv6 options are parsed, posing a risk in network communications.

Affected Version(s)

NetX Duo 0 <= 6.5.1.202602

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Microsvuln
L0stHeart
.