CVE-2025-55081 is a critical out-of-bounds read vulnerability affecting Eclipse Foundation NextX Duo before version 6.4.4, specifically within the _nx_secure_tls_process_clienthello() function of the ThreadX module. An unauthenticated attacker can exploit this by sending a crafted SSL/TLS client hello message with malformed ciphersuite or compression method lengths, leading to high impact on confidentiality and availability. With a CVSS score of 9.1, this vulnerability is easily exploitable over a network with no user interaction required. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.4.4.202503CPE matchmatch criteria | cpe:2.3:a:eclipse:threadx_netx_duo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.