NetX Duo security advisories

The table below lists published security advisories for NetX Duo, newest first. Click a GHSA ID for full details.

Published GHSA ID CVE ID Summary Severity

2026‑01‑23

GHSA‑f3rx‑xrwm‑q2rf

CVE‑2025‑55102

Eclipse ThreadX NetX Duo IPv6 denial of service

High

2025‑10‑20

GHSA‑99pw‑cp79‑2j5j

CVE‑2025‑55086

dhcvpv6 client: Unchecked Server-Side Malicious Packet

Medium

2025‑10‑17

GHSA‑vwh7‑h99r‑fvwq

CVE‑2025‑55092

Potential out of bound read in _nx_ipv4_option_process()

Medium

2025‑10‑17

GHSA‑v474‑mv4g‑v8cx

CVE‑2025‑55087

SNMPv3: No checks before parsing security parameters

Medium

2025‑10‑17

GHSA‑rf32‑h832‑hg8r

CVE‑2025‑55094

Potential out-of-bounds read in _nx_icmpv6_validate_options()

Medium

2025‑10‑17

GHSA‑c9pq‑93jp‑w649

CVE‑2025‑55093

Out of bound read and write in _nx_ipv4_packet_receive() when handling unicast DHCP messages

Medium

2025‑10‑17

GHSA‑9c77‑rgp9‑c2g2

CVE‑2025‑55085

Web http client: Unchecked Server-Side Malicious Packet

High

2025‑10‑16

GHSA‑pf5q‑r6q5‑6j2f

CVE‑2025‑55091

Potential out of bound read in _nx_ip_packet_receive()

Medium

2025‑10‑16

GHSA‑m474‑39rw‑v8gm

CVE‑2025‑55084

Off-by-one out of bound read in _nx_secure_tls_proc_clienthello_supported_versions_extension()

Medium

2025‑10‑16

GHSA‑cf2g‑j6vv‑m8c5

CVE‑2025‑55090

Potential out of bound read issue in _nx_ipv4_packet_receive()

Medium

2025‑10‑15

GHSA‑9hw5‑4xcv‑jprm

CVE‑2025‑55083

Broken bounds check in _nx_secure_tls_process_clienthello_psk_extension() doesn’t account for offset

Medium

2025‑10‑15

GHSA‑8h38‑qjhh‑mf2h

CVE‑2025‑55082

Out of bound read and possible info leak in _nx_secure_tls_psk_identity_find()

Medium

2025‑10‑15

GHSA‑5vrv‑8j5h‑h6h6

CVE‑2025‑55081

Potential out of bound read in _nx_secure_tls_process_clienthello()

Medium

2025‑04‑06

GHSA‑f42f‑6fvv‑xqx3

CVE‑2025‑2260

Eclipse ThreadX NetX Duo HTTP Component server denial of service

Medium

2025‑04‑06

GHSA‑chqp‑8vf8‑cj25

CVE‑2025‑2258

Eclipse ThreadX NetX Duo HTTP component server single PUT request integer underflow vulnerability

Medium

2025‑04‑06

GHSA‑chhp‑gmxc‑46rq

CVE‑2025‑2259

Eclipse ThreadX NetX Duo HTTP Component server chunked PUT request integer underflow

Medium

2025‑02‑21

GHSA‑pwf8‑5q9w‑m763

CVE‑2025‑0726

Eclipse ThreadX NetX Duo HTTP server denial of service vulnerability (TALOS-2024-2098)

Medium

2025‑02‑21

GHSA‑jf6x‑9mgc‑p72w

CVE‑2025‑0727

Eclipse ThreadX NetX Duo HTTP server chunked PUT request integer underflow vulnerability (TALOS-2024-2104)

Medium

2025‑02‑21

GHSA‑hqp7‑4q26‑6wqf

CVE‑2025‑0728

Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflow vulnerability (TALOS-2024-2105)

Medium

2024‑03‑26

GHSA‑h963‑7vhw‑8rpx

CVE‑2024‑2452

Integer wraparound, under-allocation, and heap buffer overflow in Eclipse ThreadX NetX Duo __portable_aligned_alloc()

High

2023‑12‑03

GHSA‑rj6h‑jjg2‑7gf3

CVE‑2023‑48315

Azure RTOS NetX Duo Remote Code Execution Vulnerability

High

2023‑12‑03

GHSA‑m2rx‑243p‑9w64

CVE‑2023‑48692

Azure RTOS NetX Duo Remote Code Execution Vulnerability

Critical

2023‑12‑03

GHSA‑fwmg‑rj6g‑w99p

CVE‑2023‑48691

Azure RTOS NetX Duo Remote Code Execution Vulnerability

High

2023‑12‑03

GHSA‑3cmf‑r288‑xhwq

CVE‑2023‑48316

Azure RTOS NetX Duo Remote Code Execution Vulnerability

Critical