CVE-2026-102761
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two packets therefore drives the XOR loop through the first packet's unused payload area and on through the second packet's `NX_PACKET` control block. The four-byte WebSocket masking key controls the bytes written, so the corruption is attacker-chosen rather than incidental.
| CWE | CWE-787 |
| Vendor | eclipse foundation |
| Product | netx duo |
| Published | Sep 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for eclipse foundation netx duo
Be the first to know when new unknown vulnerabilities affecting eclipse foundation netx duo are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Eclipse Foundation / NetX Duo
6.2.0 โค 6.5.1.202602
References
Credits
๐ leginwos ๐ adawn0106