rootpwn

high · CVSS v3 7.5

CVE-2026-93652

The CVE-2026-93652 flaw is an integer overflow in the µD3TN v0.15.0 TCPCLv3 handshake that triggers a heap overflow, allowing remote attacke

Overview

The CVE-2026-93652 flaw is an integer overflow in the µD3TN v0.15.0 TCPCLv3 handshake that triggers a heap overflow, allowing remote attackers to reliably cause a denial‑of‑service. It affects systems running the vulnerable µD3TN firmware and can interrupt critical network services. The vulnerability is exploitable without authentication and can be triggered by any external host that initiates a TCPCLv3 connection.

Description

Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS

Impact

The primary impact is loss of availability, as attackers can crash the µD3TN service and disrupt network traffic. This affects network operators, system administrators, and any services that rely on µD3TN for routing or connectivity. The attack does not compromise confidentiality or integrity, but the resulting downtime can have cascading effects on dependent applications.

Remediation

Apply the vendor‑issued patch or upgrade to a later µD3TN release that fixes the integer overflow. If an upgrade is not immediately possible, disable or block the TCPCLv3 handshake on the firewall or use ACLs to restrict access to the µD3TN port. Monitor logs for abnormal handshake attempts and consider rate‑limiting or temporary service suspension during investigation.

Risk context

The CVSS v3 score of 7.5 and high severity rating indicate a significant risk; defenders should treat this as a high‑priority issue and act promptly. No EPSS data is available, but the nature of the flaw allows reliable DoS from remote hosts.

Affected products

  • µD3TN v0.15.0
  • µD3TN TCPCLv3

Scores

Severity
high
CVSS v2
7.8
CVSS v3
7.5
CVSS v4
EPSS

DoS IntegerOverflow HeapOverflow TCPCLv3 µD3TN HighSeverity RemoteDoS

← All CVEs