Description
NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two packets therefore drives the XOR loop through the first packet's unused payload area and on through the second packet's `NX_PACKET` control block.



The four-byte WebSocket masking key controls the bytes written, so the corruption is attacker-chosen rather than incidental.
Published: 2026-09-29
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse netx Duo
Vendors & Products Eclipse
Eclipse netx Duo

Wed, 30 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title NetX Duo WebSocket Client Buffer Overwrite via Masking Key

Tue, 29 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two packets therefore drives the XOR loop through the first packet's unused payload area and on through the second packet's `NX_PACKET` control block. The four-byte WebSocket masking key controls the bytes written, so the corruption is attacker-chosen rather than incidental.
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Eclipse Netx Duo
cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-30T20:41:01.935Z

Reserved: 2026-09-29T16:22:00.376Z

Link: CVE-2026-102761

cve-icon Vulnrichment

Updated: 2026-09-30T20:40:57.457Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:13.450

Modified: 2026-09-30T21:17:05.550

Link: CVE-2026-102761

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T20:40:14Z

Weaknesses