Security Advisory – May, 2026: Denial of Service via Malformed NTP Server Address in Device Management API

Advisory ID: NEAT-SA-2026-05-16
Publication date: May 16, 2026
Last updated: May 16, 2026

Severity: Not formally scored by Neat
CVSS vector: Not scored
CVE ID: Not applicable

Summary

Configuring an excessively long NTP (time server) address through a Neat device’s management API could cause the device to enter a continuous reboot loop. In some cases, recovering from this state required a full factory reset, resulting in loss of the device’s local configuration.

Affected Products

ProductAffected versionsFixed version
Neat Pad ProNeatOS prior to 26.2.0NeatOS 26.2.0 or later
Neat Board 32NeatOS prior to 26.2.0NeatOS 26.2.0 or later

Impact

An attacker or misconfiguration that sets an excessively long NTP server address via the device management API could render the device unusable, requiring a factory reset in some cases and resulting in loss of its local configuration. This is an availability impact rather than a confidentiality or integrity impact.

Details

The device’s NTP address handling did not validate the length of the address supplied through the management API before applying it, leading to a crash loop rather than a rejected or truncated value. NTP address handling has been redesigned to safely accept full-length server hostnames regardless of the value supplied.

Remediation

Update to NeatOS 26.2.0 or later (Neat Pad Pro and Neat Board 32).

Acknowledgements

Not specified in the original release notes.

References

Contact

Questions about this advisory can be directed to security@neat.no.