RTSP Server Vulnerability in NetX Duo by Eclipse
CVE-2026-102716
8.7HIGH
What is CVE-2026-102716?
An unauthenticated client can exploit a flaw in the RTSP server of NetX Duo by sending malformed requests containing a Session header that the parser fails to convert. This leads to a gradual exhaustion of the server's packet pool. Instead of returning an appropriate RTSP status code, the server incorrectly handles the error and fails to release allocated packets. Consequently, as clients send multiple malformed requests, the available packets diminish, leading to service failures. To mitigate this issue, it is necessary to ensure proper error handling that maps failures to appropriate RTSP status codes and guarantees packet releases upon error conditions.
Affected Version(s)
eclipse-threadx/netxduo 0 <= 6.5.1
