CVE-2026-66732 HIGH

CVE-2026-66732: Sonic 3 A.I.R. Missing Source Address Validation in ConnectionManager

Vendor Eukaryot
Product sonic3air
Weakness CWE-346 · Origin validation
Published August 6, 2026
Last update August 6, 2026

CVSS base score

8.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established connections are resolved by a two-byte local connection handle alone without verifying that the datagram source address matches the registered remote address for the connection. An on-path attacker who can observe cleartext UDP traffic can inject arbitrary packets into any established session by forging the two-byte connection identifier, enabling session termination via TerminateConnectionPacket, arbitrary channel message forgery, and forged request responses without requiring IP address spoofing.

Key dates

02Disclosure timeline

August 6, 2026 CVE published
August 6, 2026 Record updated