CVE-2026-102710Critical· 9.3▾ MidnightAttacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing kernel dispatch calls, on a build with `TX_ENABLE_EVENT_TRACE`. A user-mode, memory-protected module can register an arbitra…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Attacker model / Preconditions: a loaded TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION module issuing kernel dispatch calls, on a build with TX_ENABLE_EVENT_TRACE.
A user-mode, memory-protected module can register an arbitrary function pointer as the global trace-full callback. The kernel calls it directly — no validation, no trampoline — from privileged kernel code when the trace buffer wraps.
An invalid pointer faults the kernel (DoS). A pointer into the module's own code was observed running with kernel privilege (CONTROL.nPRIV = 0), confirmed at runtime with a register capture inside that code.
eclipse-threadx/threadx <= v6.5.1.202602a_relRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102757High· 8.5An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary. The Modul…
CVE-2026-102709High· 8.4Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory
CVE-2026-102758NoneThe `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data
CVE-2026-102760High· 8.3When NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent on an active session is wiped after it has been handed to TCP
CVE-2026-102759Medium· 6.3NetX Secure TLS accepts an empty application-data record without verifying its message authentication code
CVE-2026-102761Critical· 9.3NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet