Threadx Netx Duo
Eclipse · 21 CVEs
The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process…
Jun 19, 2026
A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specia…
Jan 27, 2026
In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there…
Oct 20, 2025
Web http client: Unchecked Server-Side Malicious Packet Issue
Oct 17, 2025
In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an o…
Oct 17, 2025
Potential out-of-bounds read in _nx_icmpv6_validate_options()
Oct 17, 2025
Out of bound read and write in _nx_ipv4_packet_receive() when handling unicast DHCP messages
Oct 17, 2025
Potential out of bound read in _nx_ipv4_option_process()
Oct 17, 2025
Potential out of bound read in _nx_ip_packet_receive()
Oct 16, 2025
Potential out of bound read issue in _nx_ipv4_packet_receive() in NetX Duo
Oct 16, 2025
Out of bound read in _nx_secure_tls_proc_clienthello_supported_versions_extension()
Oct 16, 2025
Broken bounds check in Broken bounds check in _nx_secure_tls_process_clienthello_psk_extension()
Oct 15, 2025
Potential out of bound read and info leak in_nx_secure_tls_psk_identity_find()
Oct 15, 2025
Potential out of bound read in _nx_secure_tls_process_clienthello()
Oct 15, 2025
Eclipse ThreadX NetX Duo component HTTP server single PUT request integer underflow
Apr 6, 2025
Eclipse ThreadX NetX Duo HTTP component server denial of service
Apr 6, 2025
Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflow
Apr 6, 2025
Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflow
Feb 21, 2025
Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflow
Feb 21, 2025
Eclipse ThreadX NetX Duo HTTP server denial of service
Feb 21, 2025
Integer wraparound, under-allocation, and heap buffer overflow in Eclipse ThreadX NetX Duo __portable_aligned_alloc()
Mar 26, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-11576 | The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this… | HIGH | 0.46% | Jun 19, 2026 |
| CVE-2025-55102 | A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network packet of "Packet To… | HIGH | 0.40% | Jan 27, 2026 |
| CVE-2025-55086 | In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked index extracting the s… | MEDIUM | 0.41% | Oct 20, 2025 |
| CVE-2025-55085 | Web http client: Unchecked Server-Side Malicious Packet Issue | HIGH | 0.61% | Oct 17, 2025 |
| CVE-2025-55087 | In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an out-of-bound read by a crafted SNMPv3 sec… | MEDIUM | 0.46% | Oct 17, 2025 |
| CVE-2025-55094 | Potential out-of-bounds read in _nx_icmpv6_validate_options() | MEDIUM | 0.41% | Oct 17, 2025 |
| CVE-2025-55093 | Out of bound read and write in _nx_ipv4_packet_receive() when handling unicast DHCP messages | MEDIUM | 0.31% | Oct 17, 2025 |
| CVE-2025-55092 | Potential out of bound read in _nx_ipv4_option_process() | MEDIUM | 0.33% | Oct 17, 2025 |
| CVE-2025-55091 | Potential out of bound read in _nx_ip_packet_receive() | MEDIUM | 0.37% | Oct 16, 2025 |
| CVE-2025-55090 | Potential out of bound read issue in _nx_ipv4_packet_receive() in NetX Duo | MEDIUM | 0.37% | Oct 16, 2025 |
| CVE-2025-55084 | Out of bound read in _nx_secure_tls_proc_clienthello_supported_versions_extension() | MEDIUM | 0.33% | Oct 16, 2025 |
| CVE-2025-55083 | Broken bounds check in Broken bounds check in _nx_secure_tls_process_clienthello_psk_extension() | MEDIUM | 0.25% | Oct 15, 2025 |
| CVE-2025-55082 | Potential out of bound read and info leak in_nx_secure_tls_psk_identity_find() | MEDIUM | 0.25% | Oct 15, 2025 |
| CVE-2025-55081 | Potential out of bound read in _nx_secure_tls_process_clienthello() | MEDIUM | 0.37% | Oct 15, 2025 |
| CVE-2025-2259 | Eclipse ThreadX NetX Duo component HTTP server single PUT request integer underflow | MEDIUM | 0.96% | Apr 6, 2025 |
| CVE-2025-2260 | Eclipse ThreadX NetX Duo HTTP component server denial of service | HIGH | 0.96% | Apr 6, 2025 |
| CVE-2025-2258 | Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflow | MEDIUM | 0.96% | Apr 6, 2025 |
| CVE-2025-0727 | Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflow | MEDIUM | 0.76% | Feb 21, 2025 |
| CVE-2025-0728 | Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflow | MEDIUM | 0.76% | Feb 21, 2025 |
| CVE-2025-0726 | Eclipse ThreadX NetX Duo HTTP server denial of service | HIGH | 0.76% | Feb 21, 2025 |
| CVE-2024-2452 | Integer wraparound, under-allocation, and heap buffer overflow in Eclipse ThreadX NetX Duo __portable_aligned_alloc() | CRITICAL | 0.91% | Mar 26, 2024 |
Showing 1 to 21 of 21 CVEs