VYPR
Vendor

Eclipse Threadx

Products
5
CVEs
29
Across products
29
Status
Private

Products

5

Recent CVEs

29
View all 29 CVEs →
  • CVE-2026-102761CriSep 29, 2026
    risk 0.60cvss —epss 0.00

    NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two…

  • CVE-2026-102710CriSep 29, 2026
    risk 0.60cvss —epss 0.00

    Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing kernel dispatch calls, on a build with `TX_ENABLE_EVENT_TRACE`. A user-mode, memory-protected module can register an arbitrary function pointer as the global…

  • CVE-2026-102718HigSep 29, 2026
    risk 0.57cvss —epss 0.00

    hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNMP packet with a multibyte OID length…

  • CVE-2026-102716HigSep 29, 2026
    risk 0.57cvss —epss 0.00

    An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests that carry a Session header the parser cannot convert. The Session branch returns the raw NetX error code instead of an RTSP status code: ```c /*…

  • CVE-2026-102713HigSep 29, 2026
    risk 0.57cvss —epss 0.00

    The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than four bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper bound, in particular not against the protocol maximum of 4 + NX_TFTP_FILE_TRANSFER_MAX. Two things…

  • CVE-2026-102712HigSep 29, 2026
    risk 0.57cvss —epss 0.00

    On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against the total record length instead of the remaining bytes. An unauthenticated peer drives an OOB source read of up to 255 bytes, and those…

  • CVE-2026-102730HigSep 29, 2026
    risk 0.56cvss —epss 0.00

    Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated…

  • CVE-2026-102757HigSep 29, 2026
    risk 0.55cvss —epss 0.00

    An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary. The Module Manager decided whether a privileged…

  • CVE-2026-102709HigSep 29, 2026
    risk 0.55cvss —epss 0.00

    Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory. The secure firmware subsequently dereferences these attacker-controlled…

  • CVE-2026-102762HigSep 29, 2026
    risk 0.53cvss —epss 0.00

    The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool…

  • CVE-2026-102717HigSep 30, 2026
    risk 0.49cvss 7.5epss 0.00

    MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash

  • CVE-2026-102728HigSep 29, 2026
    risk 0.49cvss 7.5epss 0.00

    Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both are reached from a TLS or DTLS client…

  • CVE-2026-11576HigJun 19, 2026
    risk 0.49cvss 7.5epss 0.00

    The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file was never successfully opened. Multiple…

  • CVE-2026-102715HigSep 29, 2026
    risk 0.46cvss —epss 0.00

    Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table stores each name in a slot rounded up to a multiple of four: ```c /* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */ memory_len =…

  • CVE-2026-102714HigSep 29, 2026
    risk 0.46cvss —epss 0.00

    `_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns…

  • CVE-2026-102722MedSep 29, 2026
    risk 0.45cvss —epss 0.00

    In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.

  • CVE-2026-102721MedSep 29, 2026
    risk 0.45cvss —epss 0.00

    A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 1984). When the opcode is NX_TFTP_CODE_ERROR…

  • CVE-2026-102759MedSep 29, 2026
    risk 0.41cvss —epss 0.00

    NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive…

  • CVE-2026-102719MedSep 29, 2026
    risk 0.41cvss —epss 0.00

    Predictable DTLS HelloVerifyRequest Cookie in NetX Secure

  • CVE-2026-102727MedSep 29, 2026
    risk 0.39cvss —epss 0.00

    FTP Passive Data Connection Not Bound to the Authenticated Control Peer