Buffer Overflow Vulnerability in Domoticz's TCP Bridge for RFSEC Messages
CVE-2026-71265

7.5HIGH

Key Information:

Vendor

Domoticz

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71265?

The vulnerability in Domoticz's TCP bridge arises from improper handling of MOCHAD_RFSEC messages, where an unbounded copy of data into a fixed-size stack buffer can lead to a buffer overflow. This issue occurs without length checking during the execution of the MochadTCP::MatchLine() handler, potentially allowing an attacker on the local network to exploit these flaws and disrupt critical system operations. The default port for the TCP bridge is 1099, and since there is no authentication, attackers can easily send crafted packets, leading to stack corruption in any connected Domoticz instance.

Affected Version(s)

domoticz 0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alibek Baxtiyorov
.