Threadx Netx Duo
Vendor:
First CVE: Mar 26, 2024 · Active for 2 years
21
Total CVEs
More Total CVEs than 94% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Threadx Netx Duo over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 26, 2024
2 years ago
Most Recent CVE
Jun 19, 2026
37 days ago
CVE Severity & Scoring
Threadx Netx Duo21 CVEs
33%
52%
14%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None21 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None21 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-11576HIGH The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path | Jun 19, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-55086CRITICAL In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked index extracting the server DUID from the s | Oct 20, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-55081CRITICAL In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was missing length verification of
certain SSL/TLS client hell | Oct 15, 2025 | 9.1 | 27 | NO | NO |
CVE-2024-2452CRITICAL In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control
parameters of __portable_aligned_alloc() could cause an integer
wrap-around and an allocation smaller than ex | Mar 26, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-55085HIGH In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was missing bounds verification. A | Oct 17, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-55094HIGH In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_icmpv6_validate_options() when handlin | Oct 17, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-55102HIGH A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network packet of "Packet Too Big" with more than | Jan 27, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-55087HIGH In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an out-of-bound read by a crafted SNMPv3 security parameters. | Oct 17, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-0728HIGH In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before
version 6.4.2, an attacker can cause an integer underflow and a
subsequent denial of service by writing a ver | Feb 21, 2025 | 7.5 | 23 | NO | NO |
CVE-2025-55091MEDIUM In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ip_packet_receive() function when recei | Oct 16, 2025 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Threadx Netx Duo
Top CWEs
Versions
No cataloged versions.