HTTP Header Parsing Flaw in NextX Duo by Eclipse Foundation
CVE-2025-55085
8.8HIGH
What is CVE-2025-55085?
A vulnerability in NextX Duo prior to version 6.4.4 exists due to improper validation of HTTP header fields in the HTTP client module. This lack of bounds verification can allow a crafted server response to trigger undefined behavior, potentially compromising the integrity of the application and exposing it to further risks. It is crucial for users of affected versions to update promptly to mitigate exposure to such issues.
Affected Version(s)
NetX Duo 0 < 6.4.4
References
CVSS V4
Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ekleezg
