PT-2026-102761 · Netx Duo+1 · Netx Duo+1

·

CVE-2026-102713

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NetX Duo TFTP server (affected versions not specified)
Description The TFTP server fails to validate the upper bound of DATA datagram sizes, ignoring the protocol maximum of 4 + NX TFTP FILE TRANSFER MAX. This lack of validation leads to two primary issues. First, the server passes the nx packet length minus 4 directly to FileX via the fx file write() function. Because nx packet length represents a chain length rather than a contiguous buffer, FileX may copy data beyond the end of the first packet, resulting in a heap-buffer-overflow. This allows an attacker to write memory contents into an uploaded file, which can then be retrieved via a TFTP read request, leading to memory disclosure. Second, the nx packet copy() function uses NX WAIT FOREVER when requesting packets from the pool. If a datagram exceeds the pool capacity, the server thread suspends indefinitely, causing a denial of service where no further clients can be served.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Reject any DATA datagram where nx packet length is greater than 4 + NX TFTP FILE TRANSFER MAX before processing the copy or write calls. Replace the NX WAIT FOREVER parameter in the nx packet copy() function with a bounded wait to prevent server suspension.

Exploit

Allocation of Resources Without Limits

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102713
GHSA-WR79-332C-FF8F

Affected Products

Filex
Netx Duo