Impact
A flaw in the NetX Duo TFTP client allows an attacker to send a malformed ERROR packet that contains no terminating NUL. The client copies the error string without properly bound checking, letting the loop read up to 64 bytes past the packet boundary. This heap‑buffer‑overflow can leak adjacent packet pool memory or cause the application to crash, resulting in sensitive data exposure or denial of service.
Affected Systems
NetX Duo from the Eclipse Foundation is the affected product. No specific version information is provided in the advisory.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating medium severity. EPSS data is not available and the issue is not listed in the CISA KEV catalog. Exploitation requires network access to the TFTP server and the ability to send a crafted ERROR packet. If successful, an attacker can read memory near the buffer or crash the host, but it does not directly grant remote code execution on its own.
OpenCVE Enrichment