Missing Source Address Validation Vulnerability in Sonic 3 A.I.R. by Eukaryot
CVE-2026-66732

8.3HIGH

Key Information:

Vendor

Eukaryot

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-66732?

The Sonic 3 A.I.R. software prior to commit 2492d18 suffers from a vulnerability in the ConnectionManager due to inadequate verification of the datagram source address associated with established connections. This allows an on-path attacker to craft and inject arbitrary packets into an existing session by exploiting the reliance on a two-byte local connection handle alone. By forging this identifier, attackers can issue TerminateConnectionPacket commands, manipulate channel messages, and send forged request responses without the need for IP address spoofing, thereby compromising the integrity of the communication.

Affected Version(s)

sonic3air 0 <= 26.03.28.0

sonic3air 0 <= 26.03.28.0

sonic3air 2492d1882cd2cf1cc1d7415729ce5c4fd686cd4f

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Valentin Lobstein (Chocapikk)
.