CVE-2025-55086: Critical severity Eclipse Foundation NetXDuo vulnerability
In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked index extracting the server DUID from the server reply. With a crafted packet, an attacker could cause an out of memory read.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55086?
CVE-2025-55086 is considered a medium severity vulnerability due to its potential for causing an out of memory read.
How do I fix CVE-2025-55086?
To fix CVE-2025-55086, upgrade Eclipse Foundation NetXDuo to version 6.4.4 or later.
What versions of NetXDuo are affected by CVE-2025-55086?
CVE-2025-55086 affects all versions of Eclipse Foundation NetXDuo prior to 6.4.4.
What type of attack does CVE-2025-55086 facilitate?
CVE-2025-55086 could facilitate an attack that leads to an out of memory read, potentially crashing the affected service.
Is CVE-2025-55086 specific to any networking module?
Yes, CVE-2025-55086 specifically affects the DHCPV6 client module of the NetXDuo networking support.