Out-of-Bounds Read Vulnerability in NetX Duo from Eclipse Foundation
CVE-2025-55093
6.9MEDIUM
What is CVE-2025-55093?
Inversions of NetX Duo prior to version 6.4.4 contain a vulnerability within the networking support module that handles unicast DHCP messages. Specifically, the function _nx_ipv4_packet_receive() is susceptible to an out-of-bounds read, which can potentially lead to the corruption of 4 bytes of memory. This flaw can be exploited under certain circumstances, emphasizing the need for prompt updates to secure the affected products.
Affected Version(s)
NetX Duo 0 < 6.4.4
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Justin Stauffer
Ilja van Sprundel
