CVE-2025-2260 Information

Description

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3 an attacker can cause a denial of service by specially crafted packets. The core issue is missing closing of a file in case of an error condition resulting in the 404 error for each further file request. Users can work-around the issue by disabling the PUT request support.

This issue follows an incomplete fix of CVE-2025-0726.

Reference

https://github.com/eclipse-threadx/netxduo/commit/fb3195bbb6d0d6fe71a7a19585c008623c217f9e https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-f42f-6fvv-xqx3

Share on: