CVE-2026-102726Medium· 6.0▾ SunlitUnbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102714High· 7.1`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`)
CVE-2026-102725Medium· 6.0Out-of-bounds Read from Unvalidated MSRP Attribute List Length
CVE-2026-102721Medium· 6.9A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 198…
CVE-2026-102718High· 8.7hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNM…
CVE-2026-102712High· 8.8On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against the total record length instead of the remaining bytes
CVE-2026-102713High· 8.8The TFTP server accepts a DATA datagram of any size