CVE-2026-102762: fallo de gravedad alta en Eclipse Foundation NetX Duo
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.2epss 0.2%
probabilidad de explotación
0.2%top 90% de las CVE
explotación observada
noninguna fuente lo reporta
The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool and stops all inbound network traffic on the device until it is rebooted.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Productos afectados
Eclipse Foundation · NetX DuoCVEs relacionadas — Eclipse Foundation NetX Duo
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-55085HIGHWeb http client: Unchecked Server-Side Malicious Packet IssueEPSS 0.6%CVE-2025-55094MEDIUMPotential out-of-bounds read in _nx_icmpv6_validate_options()EPSS 0.4%CVE-2025-55091MEDIUMPotential out of bound read in _nx_ip_packet_receive()EPSS 0.4%CVE-2025-55090MEDIUMPotential out of bound read issue in _nx_ipv4_packet_receive() in NetX DuoEPSS 0.4%CVE-2025-55081MEDIUMPotential out of bound read in _nx_secure_tls_process_clienthello()EPSS 0.4%CVE-2025-55092MEDIUMPotential out of bound read in _nx_ipv4_option_process()EPSS 0.3%