Threadx Netx Duo
20 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Threadx Netx Duo, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
Threadx Netx Duo CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 3 |
| 2025-03 | 0 |
| 2025-04 | 3 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 12 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 20 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High11
- Medium7
Latest CVEs
The 15 most recently published vulnerabilities affecting Threadx Netx Duo.
- CVE-2026-11576The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally c...7.5
- CVE-2025-55086In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked index extracting the server DUID from the server reply. With...9.8
- CVE-2025-55085Web http client: Unchecked Server-Side Malicious Packet Issue7.5
- CVE-2025-55087In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an out-of-bound read by a crafted SNMPv3 security parameters.7.5
- CVE-2025-55094Potential out-of-bounds read in _nx_icmpv6_validate_options()7.5
- CVE-2025-55093Out of bound read and write in _nx_ipv4_packet_receive() when handling unicast DHCP messages5.3
- CVE-2025-55092Potential out of bound read in _nx_ipv4_option_process()5.3
- CVE-2025-55091Potential out of bound read in _nx_ip_packet_receive()6.5
- CVE-2025-55090Potential out of bound read issue in _nx_ipv4_packet_receive() in NetX Duo6.5
- CVE-2025-55084Out of bound read in _nx_secure_tls_proc_clienthello_supported_versions_extension()5.3
- CVE-2025-55083Broken bounds check in Broken bounds check in _nx_secure_tls_process_clienthello_psk_extension()5.3
- CVE-2025-55082Potential out of bound read and info leak in_nx_secure_tls_psk_identity_find()5.3
- CVE-2025-55081Potential out of bound read in _nx_secure_tls_process_clienthello()9.1
- CVE-2025-2259Eclipse ThreadX NetX Duo component HTTP server single PUT request integer underflow7.5
- CVE-2025-2260Eclipse ThreadX NetX Duo HTTP component server denial of service7.5
Product grouping is registry-driven, with AI assist and human review. How it works