← Vulnerability feed

Vulnerability record · CVE-2026-7422 · published 29 April 2026

CVE-2026-7422: Amazon freertos-plus-tcp authentication bypass by spoofing vulnerability

Amazon · Freertos Plus Tcp

Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the device's own registered endpoints, because the loopback detection mechanism skips all input validation for packets whose source MAC matches a local endpoint. To mitigate this issue, users should upgrade to the fixed version when available.

7.1 CVSS 4.0 High EPSS 0.29% · top 81.1% CWE-290 · Authentication bypass by spoofing
7.1CVSS 4.0 base score
0.29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the device's own registered endpoints, because the loopback detection mechanism skips all input validation for packets whose source MAC matches a local endpoint. To mitigate this issue, users should upgrade to the fixed version when available.

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-7422 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2024-38373Amazon freertos-plus-tcp out-of-bounds read vulnerabilityFreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the …EPSS 0.62%7.2CVE-2026-7424Amazon freertos-plus-tcp vulnerabilityInteger underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the devic…EPSS 0.37%6.1CVE-2026-7426Amazon freertos-plus-tcp out-of-bounds write vulnerabilityInsufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an ad…EPSS 0.40%6.0CVE-2026-7425Amazon freertos-plus-tcp out-of-bounds read vulnerabilityInsufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent networ…EPSS 0.38%6.0CVE-2026-7423Amazon freertos-plus-tcp vulnerabilityInteger underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a…EPSS 0.36%5.3CVE-2025-11616Amazon freertos-plus-tcp vulnerabilityA missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of ce…EPSS 0.31%5.3CVE-2025-11617Amazon freertos-plus-tcp vulnerabilityA missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with inc…EPSS 0.31%5.3CVE-2025-11618Amazon freertos-plus-tcp null pointer dereference vulnerabilityA missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing code can lead to an invalid pointer dereference when receiving a UDP/IPv…EPSS 0.34%

Source: NIST National Vulnerability Database (record CVE-2026-7422), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.