Buffer Overflow in TFTP Client for NetX Duo by Eclipse
CVE-2026-102721
6.9MEDIUM
What is CVE-2026-102721?
A vulnerability exists in the TFTP client of the NetX Duo software that can lead to a buffer overflow due to improper handling of error packets. When the TFTP server responds with a short ERROR packet, it can cause the client to read beyond the allotted buffer memory. The current implementation lacks sufficient checks on the received ERROR strings, which allows attacker-controlled data to overflow into adjacent memory. This flaw could be exploited to corrupt memory and unintentionally disclose sensitive data, impacting the stability and security of applications using the NetX Duo TFTP client.
Affected Version(s)
NetX Duo 0 <= 6.5.1
