CVE-2026-102712High· 8.8▾ TwilightOn the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against the total record length instead of the remaining bytes. An unauthenticated peer drives an OOB sou…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the
ciphersuite-list length against the total record length instead of the remaining bytes. An unauthenticated
peer drives an OOB source read of up to 255 bytes, and those bytes are echoed verbatim into the outgoing
ServerHello, disclosing adjacent process memory over the network. The crash variant fires on the first
packet.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102725Medium· 6.0Out-of-bounds Read from Unvalidated MSRP Attribute List Length
CVE-2026-102726Medium· 6.0Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read
CVE-2026-102721Medium· 6.9A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 198…
CVE-2026-102718High· 8.7hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNM…
CVE-2026-102713High· 8.8The TFTP server accepts a DATA datagram of any size
CVE-2026-102714High· 7.1`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`)