PT-2025-42611 · Eclipse Foundation+1 · Eclipse Foundation Threadx+1

Ekleezg

·

Published

2025-10-17

·

Updated

2025-10-17

·

CVE-2025-55085

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NextX Duo versions prior to 6.4.4
Description The HTTP client module in NextX Duo does not properly validate the boundaries when parsing HTTP header fields. This missing bounds verification could lead to undefined behavior if a server sends a specially crafted response. The issue resides within the network support code for Eclipse Foundation ThreadX.
Recommendations Update NextX Duo to version 6.4.4 or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-55085
GHSA-9C77-RGP9-C2G2

Affected Products

Eclipse Foundation Threadx
Netx Duo