High severityNVD Advisory· Published Sep 29, 2026· Updated Sep 29, 2026
CVE-2026-102762
CVE-2026-102762
Description
The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool and stops all inbound network traffic on the device until it is rebooted.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.