CVE-2026-102759
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is never generated or compared. Empty TLS application-data records are legal, and are commonly emitted by TLS 1.0 implementations as a BEAST mitigation.
| CWE | CWE-354 |
| Vendor | eclipse foundation |
| Product | netx duo |
| Published | Sep 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for eclipse foundation netx duo
Be the first to know when new unknown vulnerabilities affecting eclipse foundation netx duo are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Eclipse Foundation / NetX Duo
6.2.0 โค 6.5.1.202602