VendorsEclipsethreadx_netx_duoany version
Vulnerabilities

Eclipse ThreadX NetX Duo any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2024-2452
Integer wraparound, under-allocation, and heap buffer overflow in Eclipse ThreadX NetX Duo __portable_aligned_alloc()
Published 2024-03-26 · Modified
9.8EPSS 0.009
CVE-2025-55086
In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked index extracting the server DUID from the server reply. With a crafted packet, an attacker could cause an out of memory read.
Published 2025-10-20 · Analyzed
9.8EPSS 0.004
CVE-2025-55081
Potential out of bound read in _nx_secure_tls_process_clienthello()
Published 2025-10-15 · Analyzed
9.1EPSS 0.004
CVE-2025-55085
Web http client: Unchecked Server-Side Malicious Packet Issue
Published 2025-10-17 · Analyzed
8.8EPSS 0.006
CVE-2025-55102
A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network packet of "Packet Too Big" with more than 15 different source address can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.
Published 2026-01-27 · Analyzed
8.7EPSS 0.004
CVE-2025-2258
Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflow
Published 2025-04-06 · Analyzed
7.5EPSS 0.009
CVE-2025-2259
Eclipse ThreadX NetX Duo component HTTP server single PUT request integer underflow
Published 2025-04-06 · Analyzed
7.5EPSS 0.009
CVE-2025-2260
Eclipse ThreadX NetX Duo HTTP component server denial of service
Published 2025-04-06 · Analyzed
7.5EPSS 0.009
CVE-2025-0728
Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflow
Published 2025-02-21 · Analyzed
7.5EPSS 0.008
CVE-2025-0726
Eclipse ThreadX NetX Duo HTTP server denial of service
Published 2025-02-21 · Analyzed
7.5EPSS 0.008
CVE-2025-0727
Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflow
Published 2025-02-21 · Analyzed
7.5EPSS 0.008
CVE-2026-11576
The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file was never successfully opened. Multiple error branches jump to the shared cleanup label before any file open operation has occurred, causing fx_file_close() to operate on an uninitialized file handle, leading to undefined behavior, double-close issues, or memory corruption.
Published 2026-06-19 · Analyzed
7.5EPSS 0.005
CVE-2025-55087
In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an out-of-bound read by a crafted SNMPv3 security parameters.
Published 2025-10-17 · Analyzed
7.5EPSS 0.005
CVE-2025-55094
Potential out-of-bounds read in _nx_icmpv6_validate_options()
Published 2025-10-17 · Analyzed
7.5EPSS 0.004
CVE-2025-55090
Potential out of bound read issue in _nx_ipv4_packet_receive() in NetX Duo
Published 2025-10-16 · Analyzed
6.9EPSS 0.004
CVE-2025-55091
Potential out of bound read in _nx_ip_packet_receive()
Published 2025-10-16 · Analyzed
6.9EPSS 0.004
CVE-2025-55084
Out of bound read in _nx_secure_tls_proc_clienthello_supported_versions_extension()
Published 2025-10-16 · Analyzed
6.9EPSS 0.003
CVE-2025-55092
Potential out of bound read in _nx_ipv4_option_process()
Published 2025-10-17 · Analyzed
6.9EPSS 0.003
CVE-2025-55093
Out of bound read and write in _nx_ipv4_packet_receive() when handling unicast DHCP messages
Published 2025-10-17 · Analyzed
6.9EPSS 0.003
CVE-2025-55083
Broken bounds check in Broken bounds check in _nx_secure_tls_process_clienthello_psk_extension()
Published 2025-10-15 · Analyzed
6.9EPSS 0.003
CVE-2025-55082
Potential out of bound read and info leak in_nx_secure_tls_psk_identity_find()
Published 2025-10-15 · Analyzed
6.9EPSS 0.003