CVE-2026-102759

Source
https://cve.org/CVERecord?id=CVE-2026-102759
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102759.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-102759
Aliases
  • GHSA-m7j3-vh25-xc8p
Published
2026-09-29T17:28:04Z
Modified
2026-10-01T03:30:42Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
[none]
Details

NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In _nx_secure_verify_mac, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is never generated or compared.

Empty TLS application-data records are legal, and are commonly emitted by TLS 1.0 implementations as a BEAST mitigation.

Database specific
{
    "cna_assigner":  "eclipse",
    "cwe_ids":  [
        "CWE-354"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102759.json"
}
References

Affected packages

Git / github.com/eclipse-threadx/netxduo

Affected ranges

Type
GIT
Repo
https://github.com/eclipse-threadx/netxduo
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "6.2.0"
        },
        {
            "last_affected":  "6.5.1.202602"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v.*
v.6.4.4.202503_rel
v6.*
v6.2.0_rel
v6.2.1_rel
v6.3.0_rel
v6.4.0_rel
v6.4.1_rel
v6.4.2_rel
v6.4.3_rel
v6.4.4.202503a
v6.4.5.202504_rel
v6.5.0.202601_rel
v6.5.1.202602_rel

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102759.json"