CVE-2026-102758None▾ SunlitThe `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates sup…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The _nx_secure_x509_asn1_tlv_block_parse() function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.
The function reads the one-byte ASN.1 tag from the caller's buffer before checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns NX_SECURE_X509_ASN1_LENGTH_TOO_LONG, but the read has already happened one byte past the end of the buffer.
code:
nx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c
UINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,
USHORT *tlv_tag_class, ULONG *tlv_length,
const UCHAR **tlv_data, ULONG *header_length)
{
UINT current_index;
USHORT current_tag;
ULONG length;
ULONG length_bytes;
current_index = 0;
current_tag = buffer[current_index]; /* <-- read before the bounds check */
if (*buffer_length < 1)
{
return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);
}
The remainder of the function is correctly ordered. The multi-byte length path is guarded by length_bytes > 4 || length_bytes > *buffer_length before its read loop, the decoded value is checked against length > *buffer_length, and the second single-byte length read follows its own *buffer_length < 1 guard. The tag read is the only load placed ahead of its check.
netx_duo <= 6.5.1.202602Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102760High· 8.3When NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent on an active session is wiped after it has been handed to TCP
CVE-2026-102759Medium· 6.3NetX Secure TLS accepts an empty application-data record without verifying its message authentication code
CVE-2026-102761Critical· 9.3NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet
CVE-2026-102762High· 8.2The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message
CVE-2026-102757High· 8.5An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary. The Modul…
CVE-2026-102709High· 8.4Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory