HTTP Header Parsing Flaw in NextX Duo by Eclipse Foundation
CVE-2025-55085

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
17 October 2025

What is CVE-2025-55085?

A vulnerability in NextX Duo prior to version 6.4.4 exists due to improper validation of HTTP header fields in the HTTP client module. This lack of bounds verification can allow a crafted server response to trigger undefined behavior, potentially compromising the integrity of the application and exposing it to further risks. It is crucial for users of affected versions to update promptly to mitigate exposure to such issues.

Affected Version(s)

NetX Duo 0 < 6.4.4

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ekleezg
.