{"id":"CVE-2026-102761","published":"2026-09-29T18:17:13.450","lastModified":"2026-09-29T19:00:16.623","description":"NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two packets therefore drives the XOR loop through the first packet's unused payload area and on through the second packet's `NX_PACKET` control block.\n\n\n\nThe four-byte WebSocket masking key controls the bytes written, so the corruption is attacker-chosen rather than incidental.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-787"],"vendors":[],"products":[],"references":[{"url":"https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-6xgx-v7gw-qjph","tags":[]}],"exploitRefs":[{"url":"https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-6xgx-v7gw-qjph","tags":[]}],"hasPoc":true,"ai":null}