CVE-2026-102721
Awaiting Analysis Awaiting Analysis - Queue

Heap Buffer Overflow in NetX TFTP Client

Vulnerability report for CVE-2026-102721, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Eclipse Foundation

Description

A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 1984). When the opcode is NX_TFTP_CODE_ERROR the message string is copied with a loop whose only limits are the destination buffer and a NUL byte: ```c /* addons/tftp/nxd_tftp_client.c:1769 */ for (i = 0; (i < (sizeof(tftp_client_ptr -> nx_tftp_client_error_string) - 1)) && (*buffer_ptr); i++) ``` Nothing compares `buffer_ptr` against `nx_packet_append_ptr`. An ERROR packet that carries no terminating NUL, which a server controls completely, walks the loop off the end of the packet until it happens to meet a zero byte or fills the 64 byte destination. ``` ERROR: AddressSanitizer: heap-buffer-overflow READ of size 1 at 0x60d0000000c8 thread T4 #0 _nxd_tftp_client_file_read addons/tftp/nxd_tftp_client.c:1769 0x60d0000000c8 is 0 bytes to the right of 136-byte region ``` The open path has the same loop at :1327 and reports the same way. What is read lands in `nx_tftp_client_error_string`, which the application is expected to display or log, so adjacent packet pool memory ends up in whatever the device does with the error text. Add `(buffer_ptr < packet_ptr -> nx_packet_append_ptr)` to the loop condition in all three paths.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a TFTP server sending an error packet that is too short. The client reads up to 64 bytes past the received data without proper bounds checking. The error message string is copied without verifying the packet length, allowing a malicious server to read adjacent memory by omitting a null terminator.

Detection Guidance

This vulnerability involves a TFTP server sending malformed ERROR packets that cause buffer overflows. Detection requires monitoring for heap-buffer-overflow errors in TFTP client operations, particularly when processing ERROR packets. Check system logs for AddressSanitizer or similar memory error reports during TFTP operations.

Impact Analysis

An attacker could exploit this to read sensitive memory from the device running the TFTP client. This may expose confidential data or crash the system. The impact depends on what memory is adjacent to the error string buffer.

Mitigation Strategies

Apply the patch by adding (buffer_ptr < packet_ptr->nx_packet_append_ptr) to the loop condition in all three affected paths in nxd_tftp_client.c. Temporarily disable TFTP services if a patch is unavailable, or restrict TFTP server access to trusted networks only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102721. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart