CVE-2026-102720: Medium severity Eclipse Foundation NetX Duo DHCP client vulnerability

Published Sep 29, 2026
·
Updated

A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a

kilobyte past the end of the received message.

The option walk keeps a pointer and an offset in step, and the only bound check uses the offset:

c

/ addons/dhcp/nxddhcpclient.c:7538, 7572 /

while (i < length - 1)

{

... size = (++data); / data moves 1: type -> length byte / data += size + 1; / data moves size + 1 more / i += size + 1; / i moves only size + 1 /

}

A TLV option occupies size + 2 bytes. data is advanced by size + 2 in total, i by size + 1, so

the offset falls one byte behind the real read position for every option the walk skips. After

enough skipped options the check i < length - 1 still holds while data is already past the end

of the message, and the subsequent read of the type and length bytes comes from whatever follows.

A single OFFER carrying a long run of skippable options is enough:

ERROR: AddressSanitizer: heap-buffer-overflow

READ of size 1 at 0x61b000000794 thread T5

#0 nxdhcpsearchbuffer addons/dhcp/nxddhcpclient.c:7541 #1 nxdhcpgetoptionvalue addons/dhcp/nxddhcpclient.c:7082

0x61b000000794 is located 164 bytes to the right of 1648-byte region

A well formed OFFER through the same path is handled normally, the client records the offer and

moves to REQUESTING, so the difference is the option layout rather than the harness.

The read runs in the DHCP client thread while the client is still unconfigured, so it happens on

every boot in reach of a hostile DHCP responder. The values read are used to configure the

interface, which is how the disclosed bytes become observable.

Advance i by size + 2, or derive the bound from data rather than keeping a second counter.

Affected Software

1 affected component
Eclipse Foundation NetX Duo DHCP client

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Fix the DHCP option-walking logic so the offset advances by size + 2 for each TLV option, or derive the bounds directly from data instead of maintaining a second counter.

Event History

Sep 29, 2026
CVE Published
via MITRE·05:46 PM
Data Sourced
via MITRE·05:46 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue in practice?

A DHCP server can trigger it, as can anyone on the local network able to answer a client’s DHCP DISCOVER before the legitimate server. The attacker needs to send a crafted DHCP OFFER containing a long sequence of skippable options.

2

Does exploitation require prior access to the device?

The described attack is delivered through DHCP during address configuration. An attacker needs LAN-position capability to act as, or race, a DHCP server; no prior access to the client is described.

3

What happens when a malicious response is processed?

The client can read roughly a kilobyte beyond the end of the received DHCP message. The provided evidence shows an AddressSanitizer-detected heap buffer overflow read in _nx_dhcp_search_buffer.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203