📦 Threadx Netx Duo

by Eclipse

🔍 What is Threadx Netx Duo?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-55086

CRITICAL CVSS 9.8 Oct 20, 2025

This vulnerability in NetXDuo's DHCPv6 client allows attackers to cause out-of-bounds memory reads by sending specially crafted DHCPv6 packets. It affects all systems using vulnerable versions of NetX...

CVE-2025-55085

HIGH CVSS 7.5 Oct 17, 2025

This vulnerability in NextX Duo's HTTP client module allows a malicious server response to trigger undefined behavior through improper bounds checking when parsing HTTP headers. It affects systems usi...

CVE-2025-55094

HIGH CVSS 7.5 Oct 17, 2025

This vulnerability in NetX Duo's ICMPv6 packet processing allows attackers to read memory beyond intended boundaries when handling specially crafted ICMP6 options. It affects all systems using NetX Du...

CVE-2025-55087

HIGH CVSS 7.5 Oct 17, 2025

This vulnerability in NextX Duo's SNMP addon allows attackers to trigger an out-of-bounds read via specially crafted SNMPv3 security parameters. This could lead to information disclosure or system cra...

CVE-2025-2260

HIGH CVSS 7.5 Apr 6, 2025

This vulnerability in Eclipse ThreadX NetX Duo's HTTP server allows attackers to cause denial of service through specially crafted packets. The issue stems from missing file closure during error condi...

CVE-2025-2258

HIGH CVSS 7.5 Apr 6, 2025

This vulnerability in Eclipse ThreadX NetX Duo's HTTP server allows attackers to cause integer underflow and denial of service by sending specially crafted HTTP packets with Content-Length smaller tha...

CVE-2025-0728

HIGH CVSS 7.5 Feb 21, 2025

An integer underflow vulnerability in NetX HTTP server functionality of Eclipse ThreadX NetX Duo allows attackers to cause denial of service by sending specially crafted HTTP packets with mismatched C...

CVE-2025-0727

HIGH CVSS 7.5 Feb 21, 2025

An integer underflow vulnerability in NetX HTTP server functionality of Eclipse ThreadX NetX Duo allows attackers to cause denial of service by sending specially crafted HTTP packets with mismatched C...

CVE-2025-0726

HIGH CVSS 7.5 Feb 21, 2025

A denial-of-service vulnerability in Eclipse ThreadX NetX Duo's HTTP server allows attackers to exhaust file handles by sending specially crafted packets. This causes all subsequent file requests to r...

CVE-2024-2452

HIGH CVSS 7.0 Mar 26, 2024

This vulnerability in Eclipse ThreadX NetX Duo allows an attacker to cause an integer wrap-around in the __portable_aligned_alloc() function, leading to smaller-than-expected memory allocations and su...

CVE-2025-55093

MEDIUM CVSS 5.3 Oct 17, 2025

This vulnerability in NetX Duo's IPv4 packet handling allows an attacker to read 4 bytes of memory beyond allocated boundaries when processing unicast DHCP messages. This affects systems using NetX Du...

CVE-2025-55091

MEDIUM CVSS 6.5 Oct 16, 2025

This vulnerability in NetX Duo's _nx_ip_packet_receive() function allows an attacker to cause an out-of-bounds read by sending specially crafted Ethernet frames with IP type but no IP data. This could...

CVE-2025-55083

MEDIUM CVSS 5.3 Oct 15, 2025

This vulnerability in NetX Duo (part of Eclipse ThreadX) allows attackers to read two bytes beyond allocated memory boundaries due to an incorrect bounds check. It affects systems using NetX Duo versi...

CVE-2025-55082

MEDIUM CVSS 5.3 Oct 15, 2025

This vulnerability in NetX Duo's TLS implementation allows attackers to cause an out-of-bounds read by providing malformed PSK length in ClientHello messages. It affects systems using NetX Duo version...