Buffer Overflow in TFTP Client for NetX Duo by Eclipse
CVE-2026-102721

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102721?

A vulnerability exists in the TFTP client of the NetX Duo software that can lead to a buffer overflow due to improper handling of error packets. When the TFTP server responds with a short ERROR packet, it can cause the client to read beyond the allotted buffer memory. The current implementation lacks sufficient checks on the received ERROR strings, which allows attacker-controlled data to overflow into adjacent memory. This flaw could be exploited to corrupt memory and unintentionally disclose sensitive data, impacting the stability and security of applications using the NetX Duo TFTP client.

Affected Version(s)

NetX Duo 0 <= 6.5.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

L0stHeart
.