VYPR

NetXDuo

by Eclipse Foundation

CVEs (2)

  • CVE-2025-55086CriOct 20, 2025
    risk 0.64cvss 9.8epss 0.00

    In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked index extracting the server DUID from the server reply. With a crafted packet, an attacker could cause an out of memory read.

  • CVE-2025-55085HigOct 17, 2025
    risk 0.49cvss 7.5epss 0.01

    In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was missing bounds verification. A crafted server response could cause undefined behavior.