VYPR

Vendor CVEs

Eclipse Threadx

All CVEs

29 total · sorted by risk
  • CVE-2026-102761CriSep 29, 2026
    risk 0.60cvss —epss 0.00

    NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two…

  • CVE-2026-102710CriSep 29, 2026
    risk 0.60cvss —epss 0.00

    Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing kernel dispatch calls, on a build with `TX_ENABLE_EVENT_TRACE`. A user-mode, memory-protected module can register an arbitrary function pointer as the global…

  • CVE-2026-102718HigSep 29, 2026
    risk 0.57cvss —epss 0.00

    hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNMP packet with a multibyte OID length…

  • CVE-2026-102716HigSep 29, 2026
    risk 0.57cvss —epss 0.00

    An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests that carry a Session header the parser cannot convert. The Session branch returns the raw NetX error code instead of an RTSP status code: ```c /*…

  • CVE-2026-102713HigSep 29, 2026
    risk 0.57cvss —epss 0.00

    The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than four bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper bound, in particular not against the protocol maximum of 4 + NX_TFTP_FILE_TRANSFER_MAX. Two things…

  • CVE-2026-102712HigSep 29, 2026
    risk 0.57cvss —epss 0.00

    On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against the total record length instead of the remaining bytes. An unauthenticated peer drives an OOB source read of up to 255 bytes, and those…

  • CVE-2026-102730HigSep 29, 2026
    risk 0.56cvss —epss 0.00

    Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated…

  • CVE-2026-102757HigSep 29, 2026
    risk 0.55cvss —epss 0.00

    An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary. The Module Manager decided whether a privileged…

  • CVE-2026-102709HigSep 29, 2026
    risk 0.55cvss —epss 0.00

    Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory. The secure firmware subsequently dereferences these attacker-controlled…

  • CVE-2026-102762HigSep 29, 2026
    risk 0.53cvss —epss 0.00

    The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool…

  • CVE-2026-102717HigSep 30, 2026
    risk 0.49cvss 7.5epss 0.00

    MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash

  • CVE-2026-102728HigSep 29, 2026
    risk 0.49cvss 7.5epss 0.00

    Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both are reached from a TLS or DTLS client…

  • CVE-2026-11576HigJun 19, 2026
    risk 0.49cvss 7.5epss 0.00

    The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file was never successfully opened. Multiple…

  • CVE-2026-102715HigSep 29, 2026
    risk 0.46cvss —epss 0.00

    Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table stores each name in a slot rounded up to a multiple of four: ```c /* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */ memory_len =…

  • CVE-2026-102714HigSep 29, 2026
    risk 0.46cvss —epss 0.00

    `_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns…

  • CVE-2026-102722MedSep 29, 2026
    risk 0.45cvss —epss 0.00

    In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.

  • CVE-2026-102721MedSep 29, 2026
    risk 0.45cvss —epss 0.00

    A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 1984). When the opcode is NX_TFTP_CODE_ERROR…

  • CVE-2026-102759MedSep 29, 2026
    risk 0.41cvss —epss 0.00

    NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive…

  • CVE-2026-102719MedSep 29, 2026
    risk 0.41cvss —epss 0.00

    Predictable DTLS HelloVerifyRequest Cookie in NetX Secure

  • CVE-2026-102727MedSep 29, 2026
    risk 0.39cvss —epss 0.00

    FTP Passive Data Connection Not Bound to the Authenticated Control Peer

  • CVE-2026-102726MedSep 29, 2026
    risk 0.39cvss —epss 0.00

    Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read

  • CVE-2026-102725MedSep 29, 2026
    risk 0.39cvss —epss 0.00

    Out-of-bounds Read from Unvalidated MSRP Attribute List Length

  • CVE-2026-102724MedSep 29, 2026
    risk 0.39cvss —epss 0.00

    NULL Pointer Dereference When Evicting the Sole MSRP Attribute

  • CVE-2026-102723MedSep 29, 2026
    risk 0.39cvss —epss 0.00

    NULL Pointer Dereference on MSRP Attribute Table Exhaustion

  • CVE-2026-102729MedSep 29, 2026
    risk 0.38cvss —epss 0.00

    `gx_binres_theme_load()` sizes its theme buffer for the theme it was asked for, and allocates it even when the resource holds no theme with that id. A theme id at or past the theme count declared by the resource gets a buffer of zero bytes. The load pass then walks past the end…

  • CVE-2026-102711MedSep 29, 2026
    risk 0.37cvss —epss 0.00

    Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image length, so every size/offset field in…

  • CVE-2026-102720MedSep 29, 2026
    risk 0.34cvss —epss 0.00

    A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a kilobyte past the end of the received message. The option walk keeps a pointer and an offset in step, and the only bound check uses the offset: ```c /*…

  • CVE-2025-55084MedOct 16, 2025
    risk 0.34cvss 5.3epss 0.00

    In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_secure_tls_proc_clienthello_supported_versions_extension() in the extension version field.

  • CVE-2025-55095MedJan 27, 2026
    risk 0.27cvss 4.2epss 0.00

    The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. When it encounters an extended partition entry in the partition table, it recursively calls itself to mount the next logical partition. This recursion occurs…