CVE-2025-55093: Eclipse Threadx Netx Duo

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() when handling unicast DHCP messages that could cause corruption of 4 bytes of memory.

Affected products

  • Eclipse Threadx Netx Duo: before 6.4.4.202503 (fixed in 6.4.4.202503)

Published 2025-10-17. Last modified 2026-10-09.