CVE-2026-102711Medium· 5.6▾ SunlitTwo issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via _txm_module_manager_memory_load / _txm_module_manager_in_place_load — APIs that take ONLY a base pointer, no image length, so every size/offset field in TXM_MODULE_PREAMBLE is fully attacker-trusted: (1) a heap OOB read (code_size trusted as the source-image length in the code-copy loop), and (2) a control-flow-integrity / defense-in-depth gap (module entry/start/callback/stop pointers computed as code_start + preamble_offset with only a != 0 check, and the preamble checksum never verified). No controlled OOB write was found (honest — the copy destination is overflow-guarded).
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102730High· 8.6Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the contro…
CVE-2026-102726Medium· 6.0Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read
CVE-2026-102725Medium· 6.0Out-of-bounds Read from Unvalidated MSRP Attribute List Length
CVE-2026-102721Medium· 6.9A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 198…
CVE-2026-102720Medium· 5.3A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a kilobyte past the end of the received message. The option walk keeps a pointer and an offset in step, and the only bound check uses …
CVE-2026-102718High· 8.7hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNM…