VulnSea

netx_duo vulnerabilities

CVEs whose affected-version data names the netx_duo package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

17 CVEsRSS

CVE-2026-102728None
today

Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them

Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, bo…

▾ SunlitEclipse Foundation · NetX Duovia NVD
CVE-2026-102727Medium· 6.0
today

FTP Passive Data Connection Not Bound to the Authenticated Control Peer

FTP Passive Data Connection Not Bound to the Authenticated Control Peer

▾ SunlitEclipse Foundation · NetX Duovia NVD
CVE-2026-102726Medium· 6.0
today

Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read

Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read

▾ SunlitEclipse Foundation · NetX Duovia NVD
CVE-2026-102725Medium· 6.0
today

Out-of-bounds Read from Unvalidated MSRP Attribute List Length

Out-of-bounds Read from Unvalidated MSRP Attribute List Length

▾ SunlitEclipse Foundation · NetX Duovia NVD
CVE-2026-102724Medium· 6.0
today

NULL Pointer Dereference When Evicting the Sole MSRP Attribute

NULL Pointer Dereference When Evicting the Sole MSRP Attribute

▾ SunlitEclipse Foundation · NetX Duovia NVD
CVE-2026-102723Medium· 6.0
today

NULL Pointer Dereference on MSRP Attribute Table Exhaustion

NULL Pointer Dereference on MSRP Attribute Table Exhaustion

▾ SunlitEclipse Foundation · NetX Duovia NVD
CVE-2026-102722Medium· 6.9
today

In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply

In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.

▾ SunlitEclipse Foundation · NetX Duovia NVD
CVE-2026-102721Medium· 6.9
today

A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 198…

A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 198…

▾ SunlitEclipse Foundation · NetX Duovia NVD
CVE-2026-102718High· 8.7
today

hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNM…

hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNM…

▾ TwilightEclipse Foundation · NetX Duovia NVD
CVE-2026-102714High· 7.1
today

`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`)

`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is…

▾ TwilightEclipse Foundation · NetX Duovia NVD
CVE-2026-102713High· 8.8
today

The TFTP server accepts a DATA datagram of any size

The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than four bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper bound, in particular not against the protocol maximum of 4 …

▾ TwilightEclipse Foundation · NetX Duovia NVD
CVE-2026-102712High· 8.8
today

On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against the total record length instead of the remaining bytes

On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against the total record length instead of the remaining bytes. An unauthenticated peer drives an OOB sou…

▾ TwilightEclipse Foundation · NetX Duovia NVD
CVE-2026-102758None
today

The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data

The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates sup…

▾ SunlitEclipse Foundation · NetX Duovia NVD
CVE-2026-102760High· 8.3
today

When NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent on an active session is wiped after it has been handed to TCP

When NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent on an active session is wiped after it has been handed to TCP. By then the TCP layer owns the packet chain and may already have released it to the packet pool. T…

▾ TwilightEclipse Foundation · NetX Duovia NVD
CVE-2026-102759Medium· 6.3
today

NetX Secure TLS accepts an empty application-data record without verifying its message authentication code

NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and re…

▾ SunlitEclipse Foundation · NetX Duovia NVD
CVE-2026-102761Critical· 9.3
today

NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet

NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout,…

▾ MidnightEclipse Foundation · NetX Duovia NVD
CVE-2026-102762High· 8.2
today

The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message

The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a f…

▾ TwilightEclipse Foundation · NetX Duovia NVD
netx_duo vulnerabilities (CVEs) · VulnSea