CVE-2026-102762EPSS p9.9%
CVE-2026-102762CVE-2026-102762
Description
The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool and stops all inbound network traffic on the device until it is rebooted.
Scoring
| EPSS | 0.21% probability of exploitation · percentile 9.9% · 2026-10-06T12:00:23Z |
| Last modified | 2026-09-30 |