CVE-2026-71265
HIGHDomoticz MochadTCP Stack Buffer Overflow via MOCHAD_RFSEC strcpy()
Title source: cnaDescription
Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_mochadbuffer into a fixed 50-byte stack buffer tempRFSECbuf using strcpy with no length check, across three separate code branches (DS10A/KR10A/MS10A device types).
References (2)
Core 2
Core References
third-party-advisory
https://github.com/domoticz/domoticz
third-party-advisory
https://github.com/domoticz/domoticz/blob/master/hardware/MochadTCP.cpp
Scores
CVSS v3
7.5
EPSS
0.0019
EPSS Percentile
9.2%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-121
Status
published
Products (1)
domoticz/domoticz
Published
Aug 05, 2026
Tracked Since
Aug 05, 2026