Memory Overflow Vulnerability in NetX Duo's mDNS Implementation by ThreadX
CVE-2026-102715

7.1HIGH

Key Information:

Vendor
CVE Published:
29 September 2026

What is CVE-2026-102715?

A memory overflow vulnerability exists in the mDNS implementation of NetX Duo by ThreadX. This issue allows an attacker on the local network to send specially crafted mDNS records that can lead to buffer overflow in the memory allocation for transmit packets. The vulnerability stems from inadequately checked lengths of incoming names, allowing a second name that shares the same bucket to influence memory allocation, potentially corrupting nearby memory areas. Affected systems may experience unexpected behavior or crashes due to corrupted packet data, highlighting the need for proper length verification and robust memory management practices.

Affected Version(s)

eclipse-threadx/netxduo 0 <= 6.5.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

L0stHeart
.