CVE-2026-102713
Last modified
CVE-2026-102713 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than four bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper bound, in particular not against the protocol maximum of 4 + NX_TFTP_FILE_TRANSFER_MAX.
Description
The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than four bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper bound, in particular not against the protocol maximum of 4 + NX_TFTP_FILE_TRANSFER_MAX. Two things follow from that one missing check, both reachable before any authentication because TFTP has none. The handler passes `nx_packet_length - 4` straight to FileX: ```c /* addons/tftp/nxd_tftp_server.c:1863, 1889 */ status = nx_packet_copy(packet_ptr, &temp_ptr, server_ptr -> nx_tftp_server_packet_pool_ptr, NX_WAIT_FOREVER); ... fx_file_write(&(client_request_ptr -> nx_tftp_client_request_file), packet_ptr -> nx_packet_prepend_ptr + 4, packet_ptr -> nx_packet_length - 4); ``` `nx_packet_length` is the length of a chain, not of one contiguous buffer, so FileX copies past the end of the first packet: ``` ERROR: AddressSanitizer: heap-buffer-overflow READ of size 1280 at 0x621000001108 thread T5 #0 __interceptor_memcpy #1 _fx_utility_memory_copy filex/common/src/fx_utility_memory_copy.c:78 0x621000001108 is 0 bytes to the right of 4104-byte region ``` Those bytes are written into the file the attacker is uploading, and a TFTP read request hands them back, so this is a memory disclosure with a convenient retrieval channel. The same datagram also wedges the server. `nx_packet_copy` at :1863 needs ceil(nx_packet_length / pool_payload) packets and asks for them with NX_WAIT_FOREVER, so when the attacker sizes the datagram beyond what the pool holds, the server thread suspends and never returns. A liveness probe after one such datagram times out with the pool at 0 of 12 packets and the server thread suspended, and no later client is served. Reject `nx_packet_length > 4 + NX_TFTP_FILE_TRANSFER_MAX` in the DATA branch before either call, and use a bounded wait rather than NX_WAIT_FOREVER for the copy.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Eclipse Foundation | NetX Duo | <= 6.5.1.202602 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-102713?
How severe is CVE-2026-102713?
How do I fix CVE-2026-102713?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10270A vulnerability was detected in D-Link DI-7001 MINI up to 19…7.5
- CVE-2026-102709Improper validation of non-secure (NS) pointers in multiple …8.4
- CVE-2026-10271A flaw has been found in a4m4 Student-Management-System up t…6.3
- CVE-2026-102710Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MO…9.3
- CVE-2026-102711Two issues in the ThreadX loadable-module loader, reached wh…5.7
- CVE-2026-102712On the first DTLS ClientHello, the parser copies a device-cl…8.8
- CVE-2026-102714`_nx_icmpv6_validate_options()` scans the option area with `…7.1
- CVE-2026-102715Any host on the LAN can send two mDNS records and make the r…7.1
- CVE-2026-102716An unauthenticated client can drain the RTSP server's packet…8.7
- CVE-2026-102718hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNM…8.7
- CVE-2026-102719Predictable DTLS HelloVerifyRequest Cookie in NetX Secure6.3
- CVE-2026-10272A vulnerability has been found in a4m4 Student-Management-Sy…6.5
Are you affected by CVE-2026-102713?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
