CVE-2026-102721
Last modified
CVE-2026-102721 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 1984). When the opcode is NX_TFTP_CODE_ERROR the message string is copied with a loop whose only limits are the destination buffer and a NUL byte: ```c /* addons/tftp/nxd_tftp_client.c:1769 */ for (i = 0; (i < (sizeof(tftp_client_ptr -> nx_tftp_client_error_string) - 1)) && (*buffer_ptr); i++) ``` Nothing compares `buffer_ptr` against `nx_packet_append_ptr`.
Description
A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 1984). When the opcode is NX_TFTP_CODE_ERROR the message string is copied with a loop whose only limits are the destination buffer and a NUL byte: ```c /* addons/tftp/nxd_tftp_client.c:1769 */ for (i = 0; (i < (sizeof(tftp_client_ptr -> nx_tftp_client_error_string) - 1)) && (*buffer_ptr); i++) ``` Nothing compares `buffer_ptr` against `nx_packet_append_ptr`. An ERROR packet that carries no terminating NUL, which a server controls completely, walks the loop off the end of the packet until it happens to meet a zero byte or fills the 64 byte destination. ``` ERROR: AddressSanitizer: heap-buffer-overflow READ of size 1 at 0x60d0000000c8 thread T4 #0 _nxd_tftp_client_file_read addons/tftp/nxd_tftp_client.c:1769 0x60d0000000c8 is 0 bytes to the right of 136-byte region ``` The open path has the same loop at :1327 and reports the same way. What is read lands in `nx_tftp_client_error_string`, which the application is expected to display or log, so adjacent packet pool memory ends up in whatever the device does with the error text. Add `(buffer_ptr < packet_ptr -> nx_packet_append_ptr)` to the loop condition in all three paths.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Eclipse Foundation | NetX Duo | <= 6.5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-102721?
How severe is CVE-2026-102721?
How do I fix CVE-2026-102721?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-102715Any host on the LAN can send two mDNS records and make the r…7.1
- CVE-2026-102716An unauthenticated client can drain the RTSP server's packet…8.7
- CVE-2026-102718hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNM…8.7
- CVE-2026-102719Predictable DTLS HelloVerifyRequest Cookie in NetX Secure6.3
- CVE-2026-10272A vulnerability has been found in a4m4 Student-Management-Sy…6.5
- CVE-2026-102720A DHCP server, or anyone on the LAN who answers a DISCOVER f…5.3
- CVE-2026-102722In the IPv4 PASV path, the FTP Client accepts whatever addre…6.9
- CVE-2026-102723NULL Pointer Dereference on MSRP Attribute Table Exhaustion6
- CVE-2026-102724NULL Pointer Dereference When Evicting the Sole MSRP Attribu…6
- CVE-2026-102725Out-of-bounds Read from Unvalidated MSRP Attribute List Leng…6
- CVE-2026-102726Unbounded PPP IPCP Option Parsing Causes a Worker Stall and …6
- CVE-2026-102727FTP Passive Data Connection Not Bound to the Authenticated C…6
Are you affected by CVE-2026-102721?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
