VendorsEclipsethreadx_usbxany version
Vulnerabilities

Eclipse Threadx Usbx any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2022-29246
Potential buffer overflow in function DFU upload in Azure RTOS USBX
Published 2022-05-24 · Modified
9.8EPSS 0.023
CVE-2022-36063
USBX Host CDC ECM integer underflow with buffer overflow
Published 2022-10-10 · Modified
9.8EPSS 0.017
CVE-2023-48694
Azure RTOS USBX Remote Code Execution Vulnerability
Published 2023-12-05 · Modified
9.8EPSS 0.013
CVE-2023-48695
Azure RTOS USBX Remote Code Execution Vulnerability
Published 2023-12-05 · Modified
9.8EPSS 0.012
CVE-2022-29223
Buffer overflow on HUB descriptor in Azure RTOS USBX
Published 2022-05-24 · Modified
9.8EPSS 0.012
CVE-2023-48697
Azure RTOS USBX Remote Code Execution Vulnerability
Published 2023-12-05 · Modified
9.8EPSS 0.012
CVE-2023-48696
Azure RTOS USBX Remote Code Execution Vulnerability
Published 2023-12-05 · Modified
9.8EPSS 0.009
CVE-2023-48698
Azure RTOS USBX Remote Code Execution Vulnerability
Published 2023-12-05 · Modified
9.8EPSS 0.009
CVE-2022-39293
Azure RTOS USBX Host PIMA vulnerable to read integer underflow with buffer overflow
Published 2022-10-13 · Modified
9.8EPSS 0.007
CVE-2025-55100
Potential out-of-bounds read in _ux_host_class_audio10_sam_parse_func()
Published 2025-10-17 · Analyzed
9.1EPSS 0.006
CVE-2025-55095
The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. When it encounters an extended partition entry in the partition table, it recursively calls itself to mount the next logical partition. This recursion occurs in _ux_host_class_storage_partition_read(), which parses up to four partition entries. If an extended partition is found (with type UX_HOST_CLASS_STORAGE_PARTITION_EXTENDED or EXTENDED_LBA_MAPPED), the code invokes: _ux_host_class_storage_media_mount(storage, sector + _ux_utility_long_get(...)); There is no limit on the recursion depth or tracking of visited sectors. As a result, a malicious or malformed disk image can include cyclic or excessively deep chains of extended partitions, causing the function to recurse until stack overflow occurs.
Published 2026-01-27 · Analyzed
7.0EPSS 0.001
CVE-2025-55099
Potential out-of-bounds read in _ux_host_class_audio_alternate_setting_locate()
Published 2025-10-17 · Analyzed
6.1EPSS 0.004
CVE-2025-55098
Potential out-of-bounds read in _ux_host_class_audio_device_type_get()
Published 2025-10-17 · Analyzed
6.1EPSS 0.003
CVE-2025-55097
Potential out-of-bounds read in _ux_host_class_audio_streaming_sampling_get()
Published 2025-10-17 · Analyzed
6.1EPSS 0.003
CVE-2025-55096
Inadequate bounds check and potential underflow in _ux_host_class_hid_report_descriptor_get()
Published 2025-10-17 · Analyzed
6.1EPSS 0.002