PT-2026-102768 · Netx · Netx

·

CVE-2026-102721

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description A heap-buffer-overflow occurs when a TFTP server responds with a short ERROR packet. The client only verifies that the datagram is at least four bytes long, but fails to compare the buffer ptr against the nx packet append ptr when copying the message string. If an ERROR packet lacks a terminating NUL byte, the loop continues reading past the end of the packet until a zero byte is encountered or the 64-byte destination buffer is filled. This allows adjacent packet pool memory to be leaked into the nx tftp client error string variable, which may then be displayed or logged by the application. This issue affects the nxd tftp client file read() function and other receive paths in the nxd tftp client.c file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102721
GHSA-WVC9-5M9H-RVXC

Affected Products

Netx