Buffer Overflow Vulnerability in Domoticz's TCP Bridge for RFSEC Messages
CVE-2026-71265
7.5HIGH
What is CVE-2026-71265?
The vulnerability in Domoticz's TCP bridge arises from improper handling of MOCHAD_RFSEC messages, where an unbounded copy of data into a fixed-size stack buffer can lead to a buffer overflow. This issue occurs without length checking during the execution of the MochadTCP::MatchLine() handler, potentially allowing an attacker on the local network to exploit these flaws and disrupt critical system operations. The default port for the TCP bridge is 1099, and since there is no authentication, attackers can easily send crafted packets, leading to stack corruption in any connected Domoticz instance.
Affected Version(s)
domoticz 0
