OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102762

HIGH · CVSS 8.2 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability affects the NetX Duo MQTT client, which improperly handles malformed PUBLISH messages, leading to a depletion of the network driver's receive pool. This results in a denial of service, as the device becomes unable to process any inbound network traffic until it is rebooted. Organizations utilizing the NetX Duo MQTT client should prioritize addressing this issue to prevent potential service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102762
Severity
HIGH
CVSS
8.2
EPSS
0.21%

Original NVD Description

The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool and stops all inbound network traffic on the device until it is rebooted.