CVE-2025-55082: Potential out of bound read and info leak in_nx_secure_tls_psk_identity_find()
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was a potential out of bound read in nxsecuretlsprocessclienthello() because of a missing validation of PSK length provided in the user message.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Eclipse Foundation ThreadX / NetX Duoto a version that resolves this vulnerability.Fixed in 6.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55082?
CVE-2025-55082 is classified as a medium severity vulnerability due to potential out of bound read issues.
How do I fix CVE-2025-55082?
To remediate CVE-2025-55082, update Eclipse Foundation ThreadX and NetX Duo to version 6.4.4 or later.
What software versions are affected by CVE-2025-55082?
CVE-2025-55082 affects all versions of Eclipse Foundation ThreadX and NetX Duo prior to version 6.4.4.
What is the impact of CVE-2025-55082?
The impact of CVE-2025-55082 includes potential exposure to out of bounds memory access, which may lead to information disclosure or system compromise.
Is CVE-2025-55082 being actively exploited?
As of the last report, there are no confirmed active exploits for CVE-2025-55082, but updating is recommended to prevent potential attacks.