PT-2026-57570 · Nuvoton · Numaker Hsusbd

CVE-2026-10668

·

Published

2026-07-12

·

Updated

2026-07-12

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Nuvoton NuMaker HSUSBD versions prior to 4.4.0
Description The USB device-controller driver in the drivers/usb/udc/udc numaker.c file unconditionally arms the control Data IN stage within the numaker hsusbd ep trigger() function. Since the hardware cannot disarm a control Data IN already armed for a previous transfer, a host that cancels an in-flight control transfer and subsequently issues a new SETUP packet can cause the driver to become out of sync. This results in the transmission of stale data and can cause the control endpoint to permanently return NAK (Negative Acknowledgment), which is a signal indicating the device is not ready to transfer data. A malicious or buggy host can repeatedly cancel and re-issue SETUP packets to wedge the USB control endpoint, leading to a denial of service where the device stops enumerating or responding until a USB reset or re-plug occurs.
Recommendations Update to version 4.4.0.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10668
GHSA-RM28-X84J-4QRX

Affected Products

Numaker Hsusbd