PT-2026-102765 · Azure Rtos · Nextx Duo Snmp Addon

·

CVE-2026-102718

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NetX Duo SNMP addon (affected versions not specified)
Description The nx snmp utility object id get function in the NetX Duo SNMP addon fails to validate the claimed OID data length against the actual buffer size when Basic Encoding Rules (BER) multibyte length encoding is used. A remote attacker can send a crafted SNMP packet with a multibyte OID length that exceeds the available buffer, causing the parser to perform an out-of-bounds read into adjacent heap memory. These bytes are then decoded as OID component values and written into the agent's internal OID string buffer, leading to state corruption. On systems with memory protection, this can crash the SNMP agent thread and cause a denial of service, while on bare metal embedded systems without memory protection, the read may silently corrupt the internal state with heap data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102718
GHSA-7QMM-29VG-7HF8

Affected Products

Nextx Duo Snmp Addon