CVE-2025-0726: Eclipse ThreadX NetX Duo HTTP server denial of service
In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause a denial of service by specially crafted packets. The core issue is missing closing of a file in case of an error condition, resulting in the 404 error for each further file request. Users can work-around the issue by disabling the PUT request support.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.4.2 - Configuration
Work around the denial-of-service issue by disabling the PUT request functionality in the NetX HTTP server (affected: NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2).
Eclipse ThreadX NetX Duo HTTP server PUT request handling = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0726?
CVE-2025-0726 is classified as a denial of service vulnerability.
How do I fix CVE-2025-0726?
To fix CVE-2025-0726, update Eclipse ThreadX NetX Duo to version 6.4.2 or later.
What causes CVE-2025-0726?
CVE-2025-0726 is caused by the failure to close a file in error conditions, allowing an attacker to send specially crafted packets.
What impact does CVE-2025-0726 have on affected systems?
CVE-2025-0726 can lead to denial of service, preventing legitimate requests from being processed.
Which versions of Eclipse ThreadX NetX Duo are affected by CVE-2025-0726?
CVE-2025-0726 affects all versions of Eclipse ThreadX NetX Duo before 6.4.2.