NetXDuo DHCPv6 Client Out-of-Bounds Read Vulnerability

Vulnerability

A vulnerability exists in the NetXDuo networking support module for Eclipse Foundation ThreadX, specifically in versions through 6.4.3. The issue arises in the DHCPv6 client, where an unchecked index allows for improper extraction of the server DUID from server replies. This flaw can be exploited with a crafted packet, leading to an out-of-bounds read and causing undefined behavior.

Impact

Exploitation of this vulnerability could result in an out-of-bounds read, causing undefined behavior that may include memory corruption or system crashes.

Remediation

Users can upgrade to NetXDuo version 6.4.4 or later to address this vulnerability.

Added: Oct 20, 2025, 6:21 PM
Updated: Oct 20, 2025, 6:21 PM

Vulnerability Rating

Custom Algorithm
spread
9.8
impact
0.6
exploitability
6.2
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.