CVE-2025-55085

HIGH

NextX Duo <6.4.4 - Buffer Overflow

Title source: llm
STIX 2.1

Description

In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was missing bounds verification. A crafted server response could cause undefined behavior.

Scores

CVSS v3 7.5
EPSS 0.0016
EPSS Percentile 36.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-1286 CWE-125
Status published
Products (1)
eclipse/threadx_netx_duo < 6.4.4.202503
Published Oct 17, 2025
Tracked Since Feb 18, 2026