Vulnerability in FTP Client Affecting Eclipse ThreadX Vendor
CVE-2026-102722
6.9MEDIUM
What is CVE-2026-102722?
The FTP Client in Eclipse ThreadX is susceptible to an improper validation issue in the IPv4 PASV path. When a server responds with a 227 reply, the client accepts any address provided without adequate verification. This flaw enables an attacker-controlled server to redirect the FTP Client to any address, potentially leading to unauthorized information access or other malicious activities.
Affected Version(s)
NetX Duo 0 <= 6.5.1.202602
