RTSP Server Vulnerability in NetX Duo by Eclipse
CVE-2026-102716

8.7HIGH

Key Information:

Vendor
CVE Published:
29 September 2026

What is CVE-2026-102716?

An unauthenticated client can exploit a flaw in the RTSP server of NetX Duo by sending malformed requests containing a Session header that the parser fails to convert. This leads to a gradual exhaustion of the server's packet pool. Instead of returning an appropriate RTSP status code, the server incorrectly handles the error and fails to release allocated packets. Consequently, as clients send multiple malformed requests, the available packets diminish, leading to service failures. To mitigate this issue, it is necessary to ensure proper error handling that maps failures to appropriate RTSP status codes and guarantees packet releases upon error conditions.

Affected Version(s)

eclipse-threadx/netxduo 0 <= 6.5.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

L0stHeart
.