CVE-2025-2258 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

In NetX Duo component HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent…
Medium CVSS: 5.3

CVE-2025-2258

In NetX Duo component HTTP server functionality of Eclipse ThreadX NetX Duo before
version 6.4.3, an attacker can cause an integer underflow and a
subsequent denial of service by writing a very large file, by specially
crafted packets with Content-Length smaller than the data request size. A
possible workaround is to disable HTTP PUT support.




This issue follows an uncomplete fix in CVE-2025-0728.
Vendor
Eclipse
Product
Threadx Netx Duo
CWE
CWE-191
Yayın Tarihi
2025-04-06 19:15:40
Güncelleme
2025-07-31 16:34:14
Source Identifier
emo@eclipse.org
KEV Date Added
-

Kategoriler

Referanslar