Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 07 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eukaryot
Eukaryot sonic3air |
|
| Vendors & Products |
Eukaryot
Eukaryot sonic3air |
Thu, 06 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Aug 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established connections are resolved by a two-byte local connection handle alone without verifying that the datagram source address matches the registered remote address for the connection. An on-path attacker who can observe cleartext UDP traffic can inject arbitrary packets into any established session by forging the two-byte connection identifier, enabling session termination via TerminateConnectionPacket, arbitrary channel message forgery, and forged request responses without requiring IP address spoofing. | |
| Title | Sonic 3 A.I.R. Missing Source Address Validation in ConnectionManager | |
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-06T18:44:27.467Z
Reserved: 2026-07-27T16:27:47.647Z
Link: CVE-2026-66732
Updated: 2026-08-06T18:32:04.269Z
Status : Received
Published: 2026-08-06T13:18:21.773
Modified: 2026-08-06T22:18:20.840
Link: CVE-2026-66732
No data.
OpenCVE Enrichment
Updated: 2026-08-07T10:00:54Z