Description
Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read
Published: 2026-09-29
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

An unbounded parsing routine for PPP IPCP options in NetX Duo allows an attacker to send a crafted packet that triggers an out‑of‑bounds read and stalls a worker thread. The read could expose internal memory contents, while the stall can exhaust system resources and cause service interruption. The vulnerability has a CVSS score of 6, indicating moderate severity.

Affected Systems

Eclipse Foundation: NetX Duo. No specific affected versions are listed in the advisory, so all releases that include the unbounded parsing code are potentially impacted until an explicit fix is applied.

Risk and Exploitability

The CVSS score of 6 signals a moderate impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a network‑based attacker that injects malformed PPP IPCP options into the device. The exploit requires only network access to the PPP link; no local privileges are needed. If successful, the attacker can either cause a denial of service by flooding the worker thread or read confidential memory, depending on how the out‑of‑bounds read is leveraged.

Generated by OpenCVE AI on September 29, 2026 at 22:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply the patch for NetX Duo released by Eclipse Foundation, as described in the GitHub advisory.
  • Upgrade to the latest NetX Duo firmware version that contains the fix, if a separate patch is not provided separately.
  • Implement network controls to block or filter malformed PPP IPCP packets to mitigate worker stalls until a patch is applied.

Generated by OpenCVE AI on September 29, 2026 at 22:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unbounded PPP IPCP Option Parsing in NetX Duo Leads to Worker Stall and Out‑of‑Bounds Read

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read
Weaknesses CWE-125
CWE-835
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-29T18:31:44.738Z

Reserved: 2026-09-29T16:15:20.789Z

Link: CVE-2026-102726

cve-icon Vulnrichment

Updated: 2026-09-29T18:31:25.431Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:12.227

Modified: 2026-09-29T19:17:23.117

Link: CVE-2026-102726

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T22:45:18Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')