Out of Bound Read Vulnerability in NetX Duo Networking Support by Eclipse Foundation
CVE-2025-55090

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 October 2025

What is CVE-2025-55090?

In versions prior to 6.4.4, a vulnerability exists in the NetX Duo networking support module for Eclipse Foundation ThreadX. This flaw pertains to the _nx_ipv4_packet_receive() function, which may potentially lead to an out-of-bounds read when processing Ethernet frames containing fewer than 4 bytes of IP packet. This vulnerability can expose systems to various threats, emphasizing the need for timely updates to the latest versions in order to mitigate risks.

Affected Version(s)

NetX Duo 0 < 6.4.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Justin Stauffer
Ilja van Sprundel
.
CVE-2025-55090 : Out of Bound Read Vulnerability in NetX Duo Networking Support by Eclipse Foundation