CVE-2025-55085: Web http client: Unchecked Server-Side Malicious Packet Issue
In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was missing bounds verification. A crafted server response could cause undefined behavior.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55085?
CVE-2025-55085 is classified as a critical vulnerability due to its potential to cause undefined behavior in the NextX Duo HTTP client.
How do I fix CVE-2025-55085?
To remediate CVE-2025-55085, upgrade NextX Duo to version 6.4.4 or later to ensure proper bounds verification in the HTTP client module.
What systems are affected by CVE-2025-55085?
CVE-2025-55085 affects NextX Duo versions prior to 6.4.4 that utilize the HTTP client module.
What is the impact of exploiting CVE-2025-55085?
Exploiting CVE-2025-55085 can lead to undefined behavior, potentially resulting in application crashes or remote code execution.
Is there a workaround for CVE-2025-55085?
There are no known workarounds for CVE-2025-55085; the only effective mitigation is updating to the latest version.