What is CVE-2026-71265?
CVE-2026-71265 is a vulnerability in Domoticz home automation system where network-received MOCHAD_RFSEC messages are copied into a small fixed-size stack buffer without bounds checking, specifically in DS10A, KR10A, and MS10A code branches. This can lead to remote buffer overflow, and affected users should apply official patches or temporarily disable the vulnerable component.
Azərbaycanca: CVE-2026-71265 Domoticz ağıllı ev sistemindəki boşluqdur, burada şəbəkədən alınan MOCHAD_RFSEC mesajları yoxlanılmadan kiçik stack buffer-ə kopyalanır. Bu, xüsusilə DS10A, KR10A, MS10A kod budaqlarında baş verir və remote buffer overflow-a səbəb ola bilər. Təsirə məruz qalan istifadəçilər dərhal rəsmi yama tətbiq etməli və ya həssas komponenti müvəqqəti olaraq deaktiv etməlidirlər.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
Which components are affected by CVE-2026-71265 in Domoticz?
This vulnerability specifically occurs in the DS10A, KR10A, and MS10A code branches.
What can be the consequence of exploiting CVE-2026-71265?
MOCHAD_RFSEC messages are copied into a small fixed-size stack buffer without bounds checking, which can lead to remote buffer overflow.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.