CVE-2024-50596: St X-Cube-Azrt-h7rs

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c

Affected products

  • St X-Cube-Azrt-h7rs: version 1.0.0 only
  • St X-Cube-Azrtos-f4: version 1.1.0 only
  • St X-Cube-Azrtos-f7: version 1.1.0 only
  • St X-Cube-Azrtos-g0: version 1.1.0 only
  • St X-Cube-Azrtos-g4: version 2.0.0 only
  • St X-Cube-Azrtos-h7: version 3.3.0 only
  • St X-Cube-Azrtos-l4: version 2.0.0 only
  • St X-Cube-Azrtos-l5: version 2.0.0 only
  • St X-Cube-Azrtos-Wb: version 2.0.0 only
  • St X-Cube-Azrtos-Wl: version 2.0.0 only

Published 2025-04-02. Last modified 2026-06-17.