OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102718

HIGH · CVSS 8.7 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability in the NetX Duo SNMP addon allows remote attackers to exploit improper validation of OID data length, leading to out-of-bounds (OOB) reads that can corrupt the internal state of the SNMP agent. This can result in denial of service on systems with memory protection or silent corruption on unprotected embedded systems. Organizations utilizing NetX Duo SNMP should prioritize patching this vulnerability to mitigate potential disruptions and data integrity issues.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102718
Severity
HIGH
CVSS
8.7
EPSS
0.31%

Original NVD Description

hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNMP packet with a multibyte OID length larger than the available buffer, causing the parser to read past the packet buffer boundary into adjacent heap memory. the OOB bytes are decoded as OID component values and written into the agents internal OID string buffer, corrupting agent state. on systems with memory protection the OOB read poses the risk of crashing the SNMP agent thread, causing denial of service. on bare metal embedded systems without memory protection the read silently succeeds and corrupts the agents internal state with heap data.