CVE-2026-71265

HIGH

Domoticz MochadTCP Stack Buffer Overflow via MOCHAD_RFSEC strcpy()

Title source: cna
STIX 2.1

Description

Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_mochadbuffer into a fixed 50-byte stack buffer tempRFSECbuf using strcpy with no length check, across three separate code branches (DS10A/KR10A/MS10A device types).

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0019
EPSS Percentile 9.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-121
Status published
Products (1)
domoticz/domoticz
Published Aug 05, 2026
Tracked Since Aug 05, 2026