Security Advisory – May, 2026: Denial of Service via Malformed NTP Server Address in Device Management API
Advisory ID: NEAT-SA-2026-05-16
Publication date: May 16, 2026
Last updated: May 16, 2026
Severity: Not formally scored by Neat
CVSS vector: Not scored
CVE ID: Not applicable
Summary
Configuring an excessively long NTP (time server) address through a Neat device’s management API could cause the device to enter a continuous reboot loop. In some cases, recovering from this state required a full factory reset, resulting in loss of the device’s local configuration.
Affected Products
| Product | Affected versions | Fixed version |
| Neat Pad Pro | NeatOS prior to 26.2.0 | NeatOS 26.2.0 or later |
| Neat Board 32 | NeatOS prior to 26.2.0 | NeatOS 26.2.0 or later |
Impact
An attacker or misconfiguration that sets an excessively long NTP server address via the device management API could render the device unusable, requiring a factory reset in some cases and resulting in loss of its local configuration. This is an availability impact rather than a confidentiality or integrity impact.
Details
The device’s NTP address handling did not validate the length of the address supplied through the management API before applying it, leading to a crash loop rather than a rejected or truncated value. NTP address handling has been redesigned to safely accept full-length server hostnames regardless of the value supplied.
Remediation
Update to NeatOS 26.2.0 or later (Neat Pad Pro and Neat Board 32).
Acknowledgements
Not specified in the original release notes.
References
- Neat devices: Version 26.2.0 Release Notes for Neat Pad Pro and Neat Board 32
- CWE-20: Improper Input Validation
Contact
Questions about this advisory can be directed to security@neat.no.