CVE-2025-2260
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Apr 6, 2025
Updated: Apr 14, 2025
CWE ID 78
Summary
CVE-2025-2260 is a denial-of-service vulnerability affecting the NetX HTTP server functionality of Eclipse ThreadX NetX Duo prior to version 6.4.3. An attacker can trigger the issue by sending specially crafted packets, causing the server to return 404 errors for each subsequent file request. The root cause is a missing file closure in case of an error condition. Users can mitigate the risk by disabling PUT request support as a workaround. Notably, this vulnerability builds upon an incomplete fix for CVE-2025-0726.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cacti
Affected Vendors
- Cacti