OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-102762 (CVSS 8.2)

NVD · officialPublished Sep 29, 2026Risk 37/100

The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool and stops all inbound network traffic on the device until it is rebooted.

CVSS
8.2
AV:NetworkAC:HighPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source