CVE-2025-2258

In NetX Duo component HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length smaller than the data request size. A possible workaround is to disable HTTP PUT support. This issue follows an uncomplete fix in CVE-2025-0728.
Configurations

Configuration 1 (hide)

cpe:2.3:a:eclipse:threadx_netx_duo:*:*:*:*:*:*:*:*

History

31 Jul 2025, 16:34

Type Values Removed Values Added
First Time Eclipse
Eclipse threadx Netx Duo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:eclipse:threadx_netx_duo:*:*:*:*:*:*:*:*
References () https://github.com/eclipse-threadx/netxduo/commit/6c8e9d1c95d71bd4b313e1cc37d8f8841543b248 - () https://github.com/eclipse-threadx/netxduo/commit/6c8e9d1c95d71bd4b313e1cc37d8f8841543b248 - Patch
References () https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-chqp-8vf8-cj25 - () https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-chqp-8vf8-cj25 - Vendor Advisory
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2105 - () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2105 - Third Party Advisory

15 Apr 2025, 16:16

Type Values Removed Values Added
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2105 -

07 Apr 2025, 14:17

Type Values Removed Values Added
Summary
  • (es) En la funcionalidad de servidor HTTP del componente NetX Duo de Eclipse ThreadX NetX Duo anterior a la versión 6.4.3, un atacante puede provocar un desbordamiento de enteros y una denegación de servicio posterior al escribir un archivo muy grande mediante paquetes especialmente manipulados con una longitud de contenido menor que el tamaño de la solicitud de datos. Un posible workaround es deshabilitar la compatibilidad con HTTP PUT. Este problema surge tras una corrección incompleta en CVE-2025-0728.

06 Apr 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-06 19:15

Updated : 2025-07-31 16:34


NVD link : CVE-2025-2258

Mitre link : CVE-2025-2258

CVE.ORG link : CVE-2025-2258


JSON object : View

Products Affected

eclipse

  • threadx_netx_duo
CWE
CWE-191

Integer Underflow (Wrap or Wraparound)