← Vulnerability feed

Vulnerability record · CVE-2025-55094 · published 17 October 2025

CVE-2025-55094: Eclipse threadx netx duo out-of-bounds read vulnerability

Eclipse · Threadx Netx Duo

In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_icmpv6_validate_options() when handling a packet with ICMP6 options.

6.9 CVSS 4.0 Medium EPSS 0.41% · top 67.3% CWE-125 · Out-of-bounds read
6.9CVSS 4.0 base score
0.41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_icmpv6_validate_options() when handling a packet with ICMP6 options.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-55094 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-2452Eclipse threadx netx duo classic buffer overflow vulnerabilityIn Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cause an integer wrap-around and …EPSS 0.90%8.8CVE-2025-55085Eclipse threadx netx duo out-of-bounds read vulnerabilityIn NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was …EPSS 0.61%8.7CVE-2025-55102Eclipse threadx netx duo uncontrolled resource consumption vulnerabilityA denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network packet of …EPSS 0.40%7.5CVE-2026-11576Eclipse threadx netx duo double free vulnerabilityThe security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label,…EPSS 0.46%7.1CVE-2025-2260Eclipse threadx netx duo vulnerabilityIn NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause a denial of service by specially crafted pa…EPSS 0.95%7.1CVE-2025-0726Eclipse threadx netx duo vulnerabilityIn NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause a denial of service by specially crafted pa…EPSS 0.76%6.9CVE-2025-55092Eclipse threadx netx duo out-of-bounds read vulnerabilityIn Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read is…EPSS 0.33%6.9CVE-2025-55093Eclipse threadx netx duo out-of-bounds read vulnerabilityIn NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_pac…EPSS 0.31%

Source: NIST National Vulnerability Database (record CVE-2025-55094), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.