CVE-2026-102722Medium· 6.9▾ SunlitIn the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 38 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's 227 reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102727Medium· 6.0FTP Passive Data Connection Not Bound to the Authenticated Control Peer
CVE-2026-102728NoneTwo client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them
CVE-2026-102724Medium· 6.0NULL Pointer Dereference When Evicting the Sole MSRP Attribute
CVE-2026-102725Medium· 6.0Out-of-bounds Read from Unvalidated MSRP Attribute List Length
CVE-2026-102726Medium· 6.0Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read
CVE-2026-102723Medium· 6.0NULL Pointer Dereference on MSRP Attribute Table Exhaustion