PT-2026-102767 · Eclipse Foundation+1 · Eclipse Threadx Netx Duo+1

·

CVE-2026-102720

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v4.0

5.3

Medium

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description A heap-buffer-overflow occurs when a DHCP server or a malicious actor on the local area network responds to a DISCOVER message. The issue stems from an incorrect bound check during the option walk process, where a pointer and an offset are kept out of sync. Specifically, for every TLV (Type-Length-Value) option skipped, the offset falls one byte behind the actual read position. This allows the system to read approximately one kilobyte past the end of the received message if a long sequence of skippable options is provided in an OFFER message. This read operation occurs in the DHCP client thread during boot while the client is unconfigured, and the leaked bytes can be used to configure the interface, making the disclosed information observable. The flaw is located in the nx dhcp search buffer() function, which is called by nx dhcp get option value().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102720
GHSA-8HJ5-P46X-5H28

Affected Products

Eclipse Threadx Netx Duo
Netx Duo