Threadx
Vendor:
First CVE: Mar 26, 2024 · Active for 2 years
13
Total CVEs
More Total CVEs than 91% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Threadx over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 26, 2024
2 years ago
Most Recent CVE
Jan 27, 2026
178 days ago
CVE Severity & Scoring
Threadx13 CVEs
23%
69%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (46.2%)
Network7 (53.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None11 (84.6%)
Unknown0 (0.0%)
Required2 (15.4%)
Privileges Required
Low4 (30.8%)
High0 (0.0%)
None9 (69.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2452CRITICAL In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control
parameters of __portable_aligned_alloc() could cause an integer
wrap-around and an allocation smaller than ex | Mar 26, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-55080HIGH In Eclipse ThreadX before 6.4.3, when memory protection is enabled, syscall parameters verification wasn't enough, allowing an attacker to obtain an arbitrary memory read/write. | Oct 15, 2025 | 7.1 | 23 | NO | NO |
CVE-2025-0728HIGH In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before
version 6.4.2, an attacker can cause an integer underflow and a
subsequent denial of service by writing a ver | Feb 21, 2025 | 7.5 | 23 | NO | NO |
CVE-2024-2214HIGH In Eclipse ThreadX before version 6.4.0, the _Mtxinit() function in the
Xtensa port was missing an array size check causing a memory overwrite.
The affected file was ports/xtensa | Mar 26, 2024 | 7.8 | 23 | NO | NO |
CVE-2024-2212HIGH In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet()
functions from the FreeRTOS compatibility API
(utility/rtos_compatibility_layers/FreeRTOS/tx_freertos.c) we | Mar 26, 2024 | 7.8 | 23 | NO | NO |
CVE-2025-0726HIGH In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before
version 6.4.2, an attacker can cause a denial of service by specially
crafted packets. The core issue is miss | Feb 21, 2025 | 7.5 | 22 | NO | NO |
CVE-2026-0648MEDIUM The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layers/OSEK/tx_osek.c) when handling the retur | Jan 27, 2026 | 6.3 | 21 | NO | NO |
CVE-2025-2258HIGH In NetX Duo component HTTP server functionality of Eclipse ThreadX NetX Duo before
version 6.4.3, an attacker can cause an integer underflow and a
subsequent denial of service by | Apr 6, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-0727HIGH In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before
version 6.4.2, an attacker can cause an integer underflow and a
subsequent denial of service by writing a ver | Feb 21, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-55079MEDIUM In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority. In some cases the check of that maximum priority wasn't performed, allowing, as a resu | Oct 15, 2025 | 5.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Threadx
Top CWEs
Versions
No cataloged versions.