high · CVSS v3 7.5
CVE-2026-93652
The CVE-2026-93652 flaw is an integer overflow in the µD3TN v0.15.0 TCPCLv3 handshake that triggers a heap overflow, allowing remote attacke
Overview
The CVE-2026-93652 flaw is an integer overflow in the µD3TN v0.15.0 TCPCLv3 handshake that triggers a heap overflow, allowing remote attackers to reliably cause a denial‑of‑service. It affects systems running the vulnerable µD3TN firmware and can interrupt critical network services. The vulnerability is exploitable without authentication and can be triggered by any external host that initiates a TCPCLv3 connection.
Description
Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS
Impact
The primary impact is loss of availability, as attackers can crash the µD3TN service and disrupt network traffic. This affects network operators, system administrators, and any services that rely on µD3TN for routing or connectivity. The attack does not compromise confidentiality or integrity, but the resulting downtime can have cascading effects on dependent applications.
Remediation
Apply the vendor‑issued patch or upgrade to a later µD3TN release that fixes the integer overflow. If an upgrade is not immediately possible, disable or block the TCPCLv3 handshake on the firewall or use ACLs to restrict access to the µD3TN port. Monitor logs for abnormal handshake attempts and consider rate‑limiting or temporary service suspension during investigation.
Risk context
The CVSS v3 score of 7.5 and high severity rating indicate a significant risk; defenders should treat this as a high‑priority issue and act promptly. No EPSS data is available, but the nature of the flaw allows reliable DoS from remote hosts.
Affected products
- µD3TN v0.15.0
- µD3TN TCPCLv3
Scores
- Severity
- high
- CVSS v2
- 7.8
- CVSS v3
- 7.5
- CVSS v4
- —
- EPSS
- —