๐Ÿ” CVE Alert

CVE-2026-102722

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.

CWE CWE-918
Vendor eclipse foundation
Product netx duo
Published Sep 29, 2026
Last Updated Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation netx duo

Be the first to know when new unknown vulnerabilities affecting eclipse foundation netx duo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / NetX Duo
0 โ‰ค 6.5.1.202602

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-j6g2-8fm3-rm8m

Credits

๐Ÿ” suidpit ๐Ÿ” acorn421