Description
In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.
Published: 2026-09-29
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized outbound connections via FTP PASV mode
Action: Update Client
AI Analysis

Impact

The FTP client in the NetX Duo software accepts the IPv4 address supplied by the server in the 227 reply during the passive mode (PASV) transaction without verifying that the address is legitimate. Validation only checks that the reply can be parsed and that the components are non‑zero, allowing a malicious server to provide any IP address. The client will then attempt to connect to that address, potentially exposing the host to unauthorized traffic, data exfiltration, or communication with malicious destinations.

Affected Systems

The affected product is Eclipse Foundation NetX Duo, specifically its FTP client implementation. The advisory does not specify particular versions, so all releases in use are potentially impacted until a patch that validates the PASV address correctly is deployed.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting a moderate likelihood of exploitation in the wild. The likely attack vector is a malicious FTP server that can send a crafted PASV reply; this inference is based on the description of the flaw.

Generated by OpenCVE AI on September 29, 2026 at 21:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest NetX Duo firmware or software update that addresses the PASV reply validation flaw.
  • Configure the FTP client or underlying networking stack to validate IPv4 addresses received in 227 replies against expected address spaces and reject any unexpected values.
  • Deploy network monitoring or firewall rules to detect and block abnormal outbound connections originating from FTP clients, mitigating the impact of an accidental or malicious misconfiguration.

Generated by OpenCVE AI on September 29, 2026 at 21:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title FTP Client accepts arbitrary IPv4 address from passive mode reply

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-29T18:34:41.445Z

Reserved: 2026-09-29T16:15:17.733Z

Link: CVE-2026-102722

cve-icon Vulnrichment

Updated: 2026-09-29T18:34:35.914Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:11.693

Modified: 2026-09-29T19:17:22.140

Link: CVE-2026-102722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T22:00:08Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)