CVE-2026-71265: Domoticz
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_mochadbuffer into a fixed 50-byte stack buffer tempRFSECbuf using strcpy with no length check, across three separate code branches (DS10A/KR10A/MS10A device types).
Affected products
- Domoticz Domoticz: any version
Published 2026-08-05. Last modified 2026-08-26.