Out of Bound Read Vulnerability in NetX Duo by Eclipse Foundation
CVE-2025-55082

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
15 October 2025

What is CVE-2025-55082?

In versions of NetX Duo prior to 6.4.4, a potential out of bounds read exposure exists within the Eclipse Foundation's ThreadX component. This vulnerability arises due to insufficient validation of the Pre-Shared Key (PSK) length in the user-provided message during the execution of the _nx_secure_tls_process_clienthello() function. Consequently, this could lead to unintended access to memory beyond the allocated bounds, potentially compromising system integrity and security.

Affected Version(s)

NetX Duo 0 < 6.4.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Justin Stauffer
Ilya van Sprundel
.
CVE-2025-55082 : Out of Bound Read Vulnerability in NetX Duo by Eclipse Foundation