CVE-2025-2259

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 6, 2025
Updated: Apr 14, 2025
CWE ID 79

Summary

CVE-2025-2259 is a denial-of-service vulnerability affecting the NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3. An attacker can exploit this issue by sending specially crafted packets with mismatched Content-Length fields, causing an integer underflow and triggering a denial-of-service condition. This vulnerability builds upon an incomplete fix of CVE-2025-0727, and disabling HTTP PUT support is suggested as a potential workaround.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share