CVE-2026-66732

MEDIUM

Sonic 3 A.I.R. Missing Source Address Validation in ConnectionManager

Title source: cna
STIX 2.1

Description

Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established connections are resolved by a two-byte local connection handle alone without verifying that the datagram source address matches the registered remote address for the connection. An on-path attacker who can observe cleartext UDP traffic can inject arbitrary packets into any established session by forging the two-byte connection identifier, enabling session termination via TerminateConnectionPacket, arbitrary channel message forgery, and forged request responses without requiring IP address spoofing.

Scores

CVSS v3 5.9
EPSS 0.0012
EPSS Percentile 2.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-346
Status published
Products (2)
Eukaryot/sonic3air < 26.03.28.0
Eukaryot/sonic3air 2492d1882cd2cf1cc1d7415729ce5c4fd686cd4f
Published Aug 06, 2026
Tracked Since Aug 06, 2026