CVE-2025-2258

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 6, 2025
Updated: Apr 15, 2025
CWE ID 79

Summary

CVE-2025-2258 is a vulnerability affecting the NetX Duo component of Eclipse ThreadX NetX Duo, specifically its HTTP server functionality. Prior to version 6.4.3, an attacker can cause an integer underflow and subsequently trigger a denial of service by sending specially crafted packets with a Content-Length smaller than the data request size. This issue builds upon an incomplete fix identified in CVE-2025-0728. A potential workaround is to disable HTTP PUT support as a mitigation measure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share