CVE-2025-0726 Information

Description

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2 an attacker can cause a denial of service by specially crafted packets. The core issue is missing closing of a file in case of an error condition resulting in the 404 error for each further file request. Users can work-around the issue by disabling the PUT request support.

Reference

https://github.com/eclipse-threadx/netxduo/commit/c78d650be7377aae1a8704bc0ce5cc6f9f189014 https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-pwf8-5q9w-m763

Share on: