Out-of-bounds write in AirServer Connect 3: an attacker connected via Wi-Fi could potentially achieve remote code execution.
Peripheral Devices
NTCF:
NTCF-2026-98787
Product:
Connect 3
Vendor:
AirServer
Criticality:
high
Status:
fixed
Discovered:
2026-06-29
Detail:
Public
Vulnerable version:
<=2026.03.13
Fixed version:
2026.09.29
Description
In accordance with the NTC Vulnerability Disclosure Policy, technical details of this vulnerability will not be publicly disclosed.
We recommend updating AirServer Connect 3 to the latest firmware version. We thank the AirServer team for their timely response and professionalism during the responsible disclosure process.
Timeline
2026-06-29: initial discovery
2026-07-02: first contact to vendor
2026-09-30: fix by vendor
2026-10-07: public disclosure