Skip to main content

Vendor/product archive

eclipse / threadx_netx_duo CVEs

Beta · best-effort

21 CVEs tagged to eclipse / threadx_netx_duo0 Critical, 6 High, 15 Medium, 0 Low, 0 Unrated.

CVE-2026-11576

Published Jun 19, 2026

The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-55102

Published Jan 27, 2026

A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network packet of "Packet Too Big" with more tha…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55086

Published Oct 20, 2025

In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked index extracting the server DUID from the…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55085

Published Oct 17, 2025

In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was missing bounds verification. A…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55094

Published Oct 17, 2025

In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_icmpv6_validate_options() when handli…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55087

Published Oct 17, 2025

In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an out-of-bound read by a crafted SNMPv3 security parameters.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55093

Published Oct 17, 2025

In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() when handling un…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55092

Published Oct 17, 2025

In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_option_process…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55091

Published Oct 16, 2025

In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ip_packet_receive() function when rece…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55090

Published Oct 16, 2025

In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() function when re…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55084

Published Oct 16, 2025

In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_secure_tls_proc_clienthello_supported_versions_extension()…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55083

Published Oct 15, 2025

In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check resulting it out by two out of bound read.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55082

Published Oct 15, 2025

In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was a potential out of bound read in _nx_secure_tls_process_clienthello() because of a missing…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55081

Published Oct 15, 2025

In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was missing length verification of certain SSL/TLS client hel…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2260

Published Apr 6, 2025

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause a denial of service by specially crafted packets. The core issue is mis…

CVSS 7.1 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-2259

Published Apr 6, 2025

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent denial of service by writing a ve…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-2258

Published Apr 6, 2025

In NetX Duo component HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent denial of service b…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-0728

Published Feb 21, 2025

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of service by writing a ve…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-0727

Published Feb 21, 2025

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of service by writing a ve…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-0726

Published Feb 21, 2025

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause a denial of service by specially crafted packets. The core issue is mis…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-2452

Published Mar 26, 2024

In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cause an integer wrap-around and an allocation smaller than e…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1