PT-2026-68138 · Domoticz · Domoticz

·

CVE-2026-71265

·

Published

2026-08-05

·

Updated

2026-08-10

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Domoticz (affected versions not specified)
Description The MochadTCP::MatchLine() function in the hardware/MochadTCP.cpp file fails to perform length checks when copying data from the m mochadbuffer (up to 1028 bytes) into a fixed 50-byte stack buffer named tempRFSECbuf using strcpy(). This occurs across three code branches for DS10A, KR10A, and MS10A device types. A local network attacker can send a crafted packet to the Mochad TCP bridge on port 1099, which requires no authentication, to overflow tempRFSECbuf and corrupt the worker thread stack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71265

Affected Products

Domoticz