---
id: CVE-2026-102759
title: >-
  NetX Secure TLS accepts an empty application-data record without verifying its
  message authentication code
summary: >-
  NetX Secure TLS accepts an empty application-data record without verifying its
  message authentication code. In `_nx_secure_verify_mac`, a decrypted
  application record whose length equals the negotiated MAC size is treated as
  valid and re…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'
cwe:
  - CWE-354
vendor: Eclipse Foundation
product: NetX Duo
affected:
  - netx_duo >= 6.2.0 <= 6.5.1.202602
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T18:17:13.177'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102759'
references:
  - url: >-
      https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-m7j3-vh25-xc8p
    label: emo@eclipse.org
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-29T17:41:02.255Z'
---

## Overview

NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is never generated or compared.



Empty TLS application-data records are legal, and are commonly emitted by TLS 1.0 implementations as a BEAST mitigation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
