OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-102761

CRITICAL · CVSS 9.3 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability affects the NetX Duo WebSocket client, which improperly handles the unmasking cursor during packet processing, allowing an attacker to exploit this flaw by crafting malicious WebSocket frames. This can lead to arbitrary memory corruption, potentially enabling remote code execution or denial of service. Organizations using NetX Duo should prioritize patching this critical vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102761
Severity
CRITICAL
CVSS
9.3
EPSS
0.25%

Original NVD Description

NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two packets therefore drives the XOR loop through the first packet's unused payload area and on through the second packet's `NX_PACKET` control block. The four-byte WebSocket masking key controls the bytes written, so the corruption is attacker-chosen rather than incidental.