CVE-2025-55082

Severity CVSS v4.0:
MEDIUM
Type:
CWE-125 Out-of-bounds Read
Publication date:
15/10/2025
Last modified:
21/10/2025

Description

In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was a potential out of bound read in _nx_secure_tls_process_clienthello() because of a missing validation of PSK length provided in the user message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:threadx_netx_duo:*:*:*:*:*:*:*:* 6.4.3 (including)