CVE-2025-55091: Potential out of bound read in _nx_ip_packet_receive()
Published Oct 16, 2025
·Updated
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in nxippacketreceive() function when received an Ethernet with type set as IP but no IP data.
Affected Software
2 affected components
Eclipse Foundation NetX Duo<6.4.4
Eclipse threadx NetX Duo<6.4.4.202503
Event History
Oct 16, 2025
CVE Published
via MITRE·07:56 AM
Data Sourced
via MITRE·07:56 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55091?
CVE-2025-55091 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2025-55091?
To resolve CVE-2025-55091, upgrade to NetX Duo version 6.4.4 or later.
3
What systems are affected by CVE-2025-55091?
CVE-2025-55091 affects versions of Eclipse Foundation NetX Duo prior to 6.4.4.
4
What exploit type is associated with CVE-2025-55091?
CVE-2025-55091 involves an out of bounds read issue in the networking support module.
5
What function is associated with the vulnerability CVE-2025-55091?
The vulnerability CVE-2025-55091 is specifically found in the _nx_ip_packet_receive() function.