← Πίσω στην αναζήτηση CVE

CVE-2026-7422

FreeRTOS-Plus-TCP

Περιγραφή

Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the device-s own registered endpoints, because the loopback detection mechanism skips all input validation for packets whose source MAC matches a local endpoint. To mitigate this issue, users should upgrade to the fixed version when available.

CVSS 6.5EPSS 0.17700000000000002%Κίνδυνος 0.66
Προβολή πηγής
Δημοσίευση
2026-04-29 19:16:26
Επηρεαζόμενες εκδόσεις
<4.2.6,<4.4.1
Τύπος
Υλικολογισμικό
Διάνυσμα
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N