CVE-2026-66732 Details
Description
Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established connections are resolved by a two-byte local connection handle alone without verifying that the datagram source address matches the registered remote address for the connection. An on-path attacker who can observe cleartext UDP traffic can inject arbitrary packets into any established session by forging the two-byte connection identifier, enabling session termination via TerminateConnectionPacket, arbitrary channel message forgery, and forged request responses without requiring IP address spoofing.
A vulnerability exists in Sonic 3 A.I.R. versions through 26.03.28.0, where the ConnectionManager fails to validate the source address of incoming UDP datagrams for established connections. Instead, it relies solely on a two-byte local connection handle, allowing an on-path attacker to inject arbitrary packets into active sessions. This exploitation can be achieved by forging the connection identifier, enabling the termination of connections, forgery of channel messages, and manipulation of request responses, all without the need for IP address spoofing.
Users can update to the latest version of Sonic 3 A.I.R. to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-346 | Origin Validation Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Eukaryot Sonic 3 A.I.R. | <= 26.03.28.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |
Volerion