Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

CVE-2026-102713

HighCVSS 8.8 / 10
Published Sep 29, 2026·Last modified Sep 30, 2026
Affected Components(27)
eclipse-threadx/netxduo
6.2.1_rel
eclipse-threadx/netxduo
6.0_rel
eclipse-threadx/netxduo
6.1.8_rel
1 / 9
Description

The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than

four bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper bound, in particular not

against the protocol maximum of 4 + NX_TFTP_FILE_TRANSFER_MAX. Two things follow from that one

missing check, both reachable before any authentication because TFTP has none.

The handler passes nx_packet_length - 4 straight to FileX:




/* addons/tftp/nxd_tftp_server.c:1863, 1889 */



status = nx_packet_copy(packet_ptr, &temp_ptr,

                        server_ptr -> nx_tftp_server_packet_pool_ptr, NX_WAIT_FOREVER);


...



fx_file_write(&(client_request_ptr -> nx_tftp_client_request_file),

              packet_ptr -> nx_packet_prepend_ptr + 4,
              packet_ptr -> nx_packet_length - 4);


nx_packet_length is the length of a chain, not of one contiguous buffer, so FileX copies past the

end of the first packet:




ERROR: AddressSanitizer: heap-buffer-overflow



READ of size 1280 at 0x621000001108 thread T5

    #0 __interceptor_memcpy
    #1 _fx_utility_memory_copy  filex/common/src/fx_utility_memory_copy.c:78


0x621000001108 is 0 bytes to the right of 4104-byte region



Those bytes are written into the file the attacker is uploading, and a TFTP read request hands them

back, so this is a memory disclosure with a convenient retrieval channel.

The same datagram also wedges the server. nx_packet_copy at :1863 needs

ceil(nx_packet_length / pool_payload) packets and asks for them with NX_WAIT_FOREVER, so when the

attacker sizes the datagram beyond what the pool holds, the server thread suspends and never

returns. A liveness probe after one such datagram times out with the pool at 0 of 12 packets and

the server thread suspended, and no later client is served.

Reject nx_packet_length > 4 + NX_TFTP_FILE_TRANSFER_MAX in the DATA branch before either call,

and use a bounded wait rather than NX_WAIT_FOREVER for the copy.

Upload your SBOM

Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.

Risk Scores
Base Score
8.8

The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker does not need any special privileges or access rights. No user interaction is needed for the attacker to exploit this vulnerability.

Threat Intelligence
6.8

Exploitation attempts have been detected. Elevated vigilance and prompt remediation are advised.

EPSS
0.31%

The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard