Out-of-Bounds Read Vulnerability in NetX Duo from Eclipse Foundation
CVE-2025-55093

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 October 2025

What is CVE-2025-55093?

Inversions of NetX Duo prior to version 6.4.4 contain a vulnerability within the networking support module that handles unicast DHCP messages. Specifically, the function _nx_ipv4_packet_receive() is susceptible to an out-of-bounds read, which can potentially lead to the corruption of 4 bytes of memory. This flaw can be exploited under certain circumstances, emphasizing the need for prompt updates to secure the affected products.

Affected Version(s)

NetX Duo 0 < 6.4.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Justin Stauffer
Ilja van Sprundel
.
CVE-2025-55093 : Out-of-Bounds Read Vulnerability in NetX Duo from Eclipse Foundation