CVE-2026-102761: Critical severity Eclipse Foundation NetX Duo vulnerability
NetX Duo's WebSocket client resets the unmasking cursor to the first NXPACKET each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two packets therefore drives the XOR loop through the first packet's unused payload area and on through the second packet's NXPACKET control block.
The four-byte WebSocket masking key controls the bytes written, so the corruption is attacker-chosen rather than incidental.
Affected Software
Event History
Frequently Asked Questions
Who can realistically trigger the corruption?
A server that sends a masked WebSocket frame to a NetX Duo WebSocket client can trigger it when the frame is split across two chained packets. The masking key controls the bytes written into memory beyond the first packet's payload area.
Is a split frame alone sufficient to reach the vulnerable path?
The affected path requires a masked server frame split across two packets. The described corruption depends on the standard contiguous packet-pool layout, which allows the XOR loop to continue from unused payload space into the next packet's NX_PACKET control block.