CVE-2026-102759: fallo de gravedad media en Eclipse Foundation NetX Duo
Publicada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.3epss 0.2%
probabilidad de explotación
0.2%top 96% de las CVE
explotación observada
noninguna fuente lo reporta
NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is never generated or compared.
Empty TLS application-data records are legal, and are commonly emitted by TLS 1.0 implementations as a BEAST mitigation.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Productos afectados
Eclipse Foundation · NetX DuoCVEs relacionadas — Eclipse Foundation NetX Duo
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-55085HIGHWeb http client: Unchecked Server-Side Malicious Packet IssueEPSS 0.6%CVE-2025-55094MEDIUMPotential out-of-bounds read in _nx_icmpv6_validate_options()EPSS 0.4%CVE-2025-55091MEDIUMPotential out of bound read in _nx_ip_packet_receive()EPSS 0.4%CVE-2025-55090MEDIUMPotential out of bound read issue in _nx_ipv4_packet_receive() in NetX DuoEPSS 0.4%CVE-2025-55081MEDIUMPotential out of bound read in _nx_secure_tls_process_clienthello()EPSS 0.4%CVE-2025-55092MEDIUMPotential out of bound read in _nx_ipv4_option_process()EPSS 0.3%