Out-of-bounds Read Vulnerability in Eclipse ThreadX Network Stack
CVE-2026-102725

6MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102725?

An out-of-bounds read vulnerability exists in the Eclipse ThreadX Network Stack due to an unvalidated MSRP attribute list length. This flaw allows an attacker to potentially read sensitive information beyond the intended buffer, leading to data exposure and integrity risks. Proper validation mechanisms should be implemented to prevent exploitation of this vulnerability.

Affected Version(s)

NetX Duo 0 <= 6.5.1.202602

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wsparks-vc
.