Impact
The FTP client in the NetX Duo software accepts the IPv4 address supplied by the server in the 227 reply during the passive mode (PASV) transaction without verifying that the address is legitimate. Validation only checks that the reply can be parsed and that the components are non‑zero, allowing a malicious server to provide any IP address. The client will then attempt to connect to that address, potentially exposing the host to unauthorized traffic, data exfiltration, or communication with malicious destinations.
Affected Systems
The affected product is Eclipse Foundation NetX Duo, specifically its FTP client implementation. The advisory does not specify particular versions, so all releases in use are potentially impacted until a patch that validates the PASV address correctly is deployed.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting a moderate likelihood of exploitation in the wild. The likely attack vector is a malicious FTP server that can send a crafted PASV reply; this inference is based on the description of the flaw.
OpenCVE Enrichment