CVE-2026-102762
Awaiting Analysis Awaiting Analysis - Queue

NetX Duo MQTT Client Packet Exhaustion Vulnerability

Vulnerability report for CVE-2026-102762, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Eclipse Foundation

Description

The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool and stops all inbound network traffic on the device until it is rebooted.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
eclipse netx_duo_mqtt_client *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-401 The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the NetX Duo MQTT client leaking packets carrying malformed PUBLISH messages. Each malformed message consumes one packet or chain of packets from the network driver's receive pool without returning it. Repeated attacks can exhaust the pool, halting all inbound network traffic until the device is rebooted.

Detection Guidance

Detecting this vulnerability requires monitoring for malformed MQTT PUBLISH messages that exhaust the network driver's receive pool. Use network sniffing tools like tcpdump or Wireshark to capture and analyze MQTT traffic for malformed packets. Check device logs for unusual packet exhaustion or network traffic drops. Monitor memory pools on affected devices for abnormal depletion.

Impact Analysis

An attacker could exploit this to disrupt network communication on the affected device by sending a few dozen malformed messages. This could lead to denial of service, preventing the device from receiving any inbound traffic until rebooted.

Mitigation Strategies

Immediately update the NetX Duo MQTT client to the latest patched version. Implement network traffic filtering to block malformed MQTT PUBLISH messages at the firewall or network gateway. Restrict MQTT traffic to trusted sources only. Reboot affected devices to clear the exhausted packet pool if the issue is already occurring.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102762. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart