CVE-2025-55085: Eclipse Threadx Netx Duo
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was missing bounds verification. A crafted server response could cause undefined behavior.
Affected products
- Eclipse Threadx Netx Duo: before 6.4.4.202503 (fixed in 6.4.4.202503)
Published 2025-10-17. Last modified 2026-10-09.