MQTT Client Vulnerability in NetX Duo by ExpressLogic
CVE-2026-102762
8.2HIGH
What is CVE-2026-102762?
The NetX Duo MQTT client has a critical issue where it leaks packets upon receiving malformed PUBLISH messages. Each malformed message consumes a packet from the network driver's receive pool, leading to an operational failure as the pool becomes exhausted. This situation results in a halt of all inbound network traffic on the device until a reboot is performed, impacting overall device functionality and reliability.
Affected Version(s)
NetX Duo 6.0 <= 6.5.1.202602
NetX Duo 6.5.2.202603
