NetX Duo security advisories
The table below lists published security advisories for NetX Duo, newest first. Click a GHSA ID for full details.
| Published | GHSA ID | CVE ID | Summary | Severity |
|---|---|---|---|---|
2026‑01‑23 |
CVE‑2025‑55102 |
Eclipse ThreadX NetX Duo IPv6 denial of service |
High |
|
2025‑10‑20 |
CVE‑2025‑55086 |
dhcvpv6 client: Unchecked Server-Side Malicious Packet |
Medium |
|
2025‑10‑17 |
CVE‑2025‑55092 |
Potential out of bound read in _nx_ipv4_option_process() |
Medium |
|
2025‑10‑17 |
CVE‑2025‑55087 |
SNMPv3: No checks before parsing security parameters |
Medium |
|
2025‑10‑17 |
CVE‑2025‑55094 |
Potential out-of-bounds read in _nx_icmpv6_validate_options() |
Medium |
|
2025‑10‑17 |
CVE‑2025‑55093 |
Out of bound read and write in _nx_ipv4_packet_receive() when handling unicast DHCP messages |
Medium |
|
2025‑10‑17 |
CVE‑2025‑55085 |
Web http client: Unchecked Server-Side Malicious Packet |
High |
|
2025‑10‑16 |
CVE‑2025‑55091 |
Potential out of bound read in _nx_ip_packet_receive() |
Medium |
|
2025‑10‑16 |
CVE‑2025‑55084 |
Off-by-one out of bound read in _nx_secure_tls_proc_clienthello_supported_versions_extension() |
Medium |
|
2025‑10‑16 |
CVE‑2025‑55090 |
Potential out of bound read issue in _nx_ipv4_packet_receive() |
Medium |
|
2025‑10‑15 |
CVE‑2025‑55083 |
Broken bounds check in _nx_secure_tls_process_clienthello_psk_extension() doesn’t account for offset |
Medium |
|
2025‑10‑15 |
CVE‑2025‑55082 |
Out of bound read and possible info leak in _nx_secure_tls_psk_identity_find() |
Medium |
|
2025‑10‑15 |
CVE‑2025‑55081 |
Potential out of bound read in _nx_secure_tls_process_clienthello() |
Medium |
|
2025‑04‑06 |
CVE‑2025‑2260 |
Eclipse ThreadX NetX Duo HTTP Component server denial of service |
Medium |
|
2025‑04‑06 |
CVE‑2025‑2258 |
Eclipse ThreadX NetX Duo HTTP component server single PUT request integer underflow vulnerability |
Medium |
|
2025‑04‑06 |
CVE‑2025‑2259 |
Eclipse ThreadX NetX Duo HTTP Component server chunked PUT request integer underflow |
Medium |
|
2025‑02‑21 |
CVE‑2025‑0726 |
Eclipse ThreadX NetX Duo HTTP server denial of service vulnerability (TALOS-2024-2098) |
Medium |
|
2025‑02‑21 |
CVE‑2025‑0727 |
Eclipse ThreadX NetX Duo HTTP server chunked PUT request integer underflow vulnerability (TALOS-2024-2104) |
Medium |
|
2025‑02‑21 |
CVE‑2025‑0728 |
Eclipse ThreadX NetX Duo HTTP server single PUT request integer underflow vulnerability (TALOS-2024-2105) |
Medium |
|
2024‑03‑26 |
CVE‑2024‑2452 |
Integer wraparound, under-allocation, and heap buffer overflow in Eclipse ThreadX NetX Duo __portable_aligned_alloc() |
High |
|
2023‑12‑03 |
CVE‑2023‑48315 |
Azure RTOS NetX Duo Remote Code Execution Vulnerability |
High |
|
2023‑12‑03 |
CVE‑2023‑48692 |
Azure RTOS NetX Duo Remote Code Execution Vulnerability |
Critical |
|
2023‑12‑03 |
CVE‑2023‑48691 |
Azure RTOS NetX Duo Remote Code Execution Vulnerability |
High |
|
2023‑12‑03 |
CVE‑2023‑48316 |
Azure RTOS NetX Duo Remote Code Execution Vulnerability |
Critical |