CVE-2025-2260 – Eclipse ThreadX NetX Duo HTTP Server Denial of Service Vulnerability

CVE ID : CVE-2025-2260

Published : April 6, 2025, 7:15 p.m. | 8 hours, 9 minutes ago

Description : In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before
version 6.4.3, an attacker can cause a denial of service by specially
crafted packets. The core issue is missing closing of a file in case of
an error condition, resulting in the 404 error for each further file
request. Users can work-around the issue by disabling the PUT request
support.

This issue follows an incomplete fix of CVE-2025-0726.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…CVE ID : CVE-2025-2260

Published : April 6, 2025, 7:15 p.m. | 8 hours, 9 minutes ago

Description : In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before
version 6.4.3, an attacker can cause a denial of service by specially
crafted packets. The core issue is missing closing of a file in case of
an error condition, resulting in the 404 error for each further file
request. Users can work-around the issue by disabling the PUT request
support.

This issue follows an incomplete fix of CVE-2025-0726.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…