PT-2026-102761 · Netx Duo+1 · Netx Duo+1
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
NetX Duo TFTP server (affected versions not specified)
Description
The TFTP server fails to validate the upper bound of DATA datagram sizes, ignoring the protocol maximum of 4 +
NX TFTP FILE TRANSFER MAX. This lack of validation leads to two primary issues. First, the server passes the nx packet length minus 4 directly to FileX via the fx file write() function. Because nx packet length represents a chain length rather than a contiguous buffer, FileX may copy data beyond the end of the first packet, resulting in a heap-buffer-overflow. This allows an attacker to write memory contents into an uploaded file, which can then be retrieved via a TFTP read request, leading to memory disclosure. Second, the nx packet copy() function uses NX WAIT FOREVER when requesting packets from the pool. If a datagram exceeds the pool capacity, the server thread suspends indefinitely, causing a denial of service where no further clients can be served.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Reject any DATA datagram where
nx packet length is greater than 4 + NX TFTP FILE TRANSFER MAX before processing the copy or write calls.
Replace the NX WAIT FOREVER parameter in the nx packet copy() function with a bounded wait to prevent server suspension.Exploit
Allocation of Resources Without Limits
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Filex
Netx Duo