Description
A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the



received datagram.



Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229,



1521, 1984). When the opcode is NX_TFTP_CODE_ERROR the message string is copied with a loop whose



only limits are the destination buffer and a NUL byte:



```c



/* addons/tftp/nxd_tftp_client.c:1769 */



for (i = 0; (i < (sizeof(tftp_client_ptr -> nx_tftp_client_error_string) - 1)) && (*buffer_ptr); i++)



```



Nothing compares `buffer_ptr` against `nx_packet_append_ptr`. An ERROR packet that carries no



terminating NUL, which a server controls completely, walks the loop off the end of the packet until



it happens to meet a zero byte or fills the 64 byte destination.



```



ERROR: AddressSanitizer: heap-buffer-overflow



READ of size 1 at 0x60d0000000c8 thread T4

#0 _nxd_tftp_client_file_read addons/tftp/nxd_tftp_client.c:1769


0x60d0000000c8 is 0 bytes to the right of 136-byte region



```



The open path has the same loop at :1327 and reports the same way. What is read lands in



`nx_tftp_client_error_string`, which the application is expected to display or log, so adjacent



packet pool memory ends up in whatever the device does with the error text.



Add `(buffer_ptr < packet_ptr -> nx_packet_append_ptr)` to the loop condition in all three paths.
Published: 2026-09-29
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Information disclosure via buffer overflow
Action: Patch Now
AI Analysis

Impact

A flaw in the NetX Duo TFTP client allows an attacker to send a malformed ERROR packet that contains no terminating NUL. The client copies the error string without properly bound checking, letting the loop read up to 64 bytes past the packet boundary. This heap‑buffer‑overflow can leak adjacent packet pool memory or cause the application to crash, resulting in sensitive data exposure or denial of service.

Affected Systems

NetX Duo from the Eclipse Foundation is the affected product. No specific version information is provided in the advisory.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.9, indicating medium severity. EPSS data is not available and the issue is not listed in the CISA KEV catalog. Exploitation requires network access to the TFTP server and the ability to send a crafted ERROR packet. If successful, an attacker can read memory near the buffer or crash the host, but it does not directly grant remote code execution on its own.

Generated by OpenCVE AI on September 29, 2026 at 21:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or update NetX Duo to the latest version that corrects the TFTP client error string copy loop.
  • If an update is not immediately available, manually modify the code by adding the condition `(buffer_ptr < packet_ptr->nx_packet_append_ptr)` to the loop in all three vulnerable paths to prevent overrunning the buffer.
  • Disable the TFTP service on devices that do not require it to eliminate the attack surface.

Generated by OpenCVE AI on September 29, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title TFTP Client Buffer Overflow via Malformed ERROR Packet

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 1984). When the opcode is NX_TFTP_CODE_ERROR the message string is copied with a loop whose only limits are the destination buffer and a NUL byte: ```c /* addons/tftp/nxd_tftp_client.c:1769 */ for (i = 0; (i < (sizeof(tftp_client_ptr -> nx_tftp_client_error_string) - 1)) && (*buffer_ptr); i++) ``` Nothing compares `buffer_ptr` against `nx_packet_append_ptr`. An ERROR packet that carries no terminating NUL, which a server controls completely, walks the loop off the end of the packet until it happens to meet a zero byte or fills the 64 byte destination. ``` ERROR: AddressSanitizer: heap-buffer-overflow READ of size 1 at 0x60d0000000c8 thread T4 #0 _nxd_tftp_client_file_read addons/tftp/nxd_tftp_client.c:1769 0x60d0000000c8 is 0 bytes to the right of 136-byte region ``` The open path has the same loop at :1327 and reports the same way. What is read lands in `nx_tftp_client_error_string`, which the application is expected to display or log, so adjacent packet pool memory ends up in whatever the device does with the error text. Add `(buffer_ptr < packet_ptr -> nx_packet_append_ptr)` to the loop condition in all three paths.
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-29T18:36:05.599Z

Reserved: 2026-09-29T16:15:17.020Z

Link: CVE-2026-102721

cve-icon Vulnrichment

Updated: 2026-09-29T18:35:40.497Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:11.540

Modified: 2026-09-29T19:17:21.417

Link: CVE-2026-102721

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T22:00:08Z

Weaknesses