Security Advisory

CVE-2025-2258

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-04-06 18:50:42
Last updated 2025-04-15 16:03:10
Assigner eclipse
CVSS score 5.3
State PUBLISHED

Description

In NetX Duo component HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length smaller than the data request size. A possible workaround is to disable HTTP PUT support. This issue follows an uncomplete fix in CVE-2025-0728.