{"id":"CVE-2026-102722","published":"2026-09-29T18:17:11.693","lastModified":"2026-09-29T19:17:22.140","description":"In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-918"],"vendors":[],"products":[],"references":[{"url":"https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-j6g2-8fm3-rm8m","tags":[]}],"exploitRefs":[{"url":"https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-j6g2-8fm3-rm8m","tags":[]}],"hasPoc":true,"ai":null}