CVE-2025-55090: Eclipse Threadx Netx Duo

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() function when received an Ethernet frame with less than 4 bytes of IP packet.

Affected products

  • Eclipse Threadx Netx Duo: before 6.4.4.202503 (fixed in 6.4.4.202503)

Published 2025-10-16. Last modified 2026-10-08.