CVE-2026-10672 is a high-severity out-of-bounds read vulnerability in Zephyr's LwM2M firmware update pull handling, affecting the default-enabled firmware pull support path from version 3.0.0 through 4.4.0. The flaw is in the pull-context logic in the LwM2M stack, where a server-supplied firmware Package URI is copied from a larger buffer into a fixed-size static destination buffer using a fixed-length memcpy without validating the actual URI length and without guaranteeing NUL termination. When an attacker supplies a Package URI whose length fills the destination buffer exactly, the copied buffer is left unterminated and is later processed as a C string by URL parsing, peer parsing, and CoAP option construction routines that rely on strlen. This causes reads past the end of the buffer into adjacent static memory. The over-read data can then be incorporated into outbound protocol messages, disclosing memory contents, and the invalid string handling can also destabilize the device and trigger a crash.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact exploit/PoC set for CVE-2026-10672 affecting Zephyr RTOS LwM2M firmware-update pull handling. It contains two code artifacts: a Python network-delivery exploit and a C standalone reproduction. The vulnerability is an out-of-bounds read caused by copying exactly 128 bytes of a server-supplied Package URI into context.uri[128] without ensuring NUL termination; later strlen() and downstream URI/CoAP handling read beyond the buffer. The practical impact is information disclosure: adjacent memory from the firmware pull context can be exfiltrated in the outbound CoAP PROXY_URI option when the device attempts to fetch firmware. Repository structure: README.md documents the CVE, affected/fixed versions, root cause, usage, and threat model. lwm2m_evil_server.py is the main exploit component: a minimal dependency-free CoAP/LwM2M server/client-side packet sender that hand-encodes CoAP PUT and POST messages. It writes an oversized Package URI to LwM2M resource /5/0/1 and then triggers update execution via /5/0/2. It supports dry-run packet generation, configurable target IP/port, URI length, and optional listening for responses. poc.c is a deterministic local reproduction of the vulnerable and fixed code paths. It re-declares the relevant firmware_pull_context layout, simulates the vulnerable memcpy/strlen flow, demonstrates leakage into a proxy_uri_option buffer, and includes an AddressSanitizer-assisted proof of the OOB read. Main exploit capabilities: (1) remote network triggering against vulnerable Zephyr LwM2M clients over CoAP/UDP, (2) attacker-controlled oversized URI generation in the 128-254 byte range, (3) triggering the firmware pull path via LwM2M Execute, and (4) demonstrating or inducing leakage of adjacent memory such as flags, callback pointers, and DTLS/PSK-related context. This is not merely a detector; it is an operational PoC with a concrete exploit path and a reproducible local demonstration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.