Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.2) | 0.21% | — | Netx DUO Mqtt ClientAI | 29/9/2026 | 30/9/2026 | The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool and stops all inbound network traffic on… | |
| Pendiente de análisis | Crítica (9.3) | 0.25% | — | Microsoft Netx DUOAI | 29/9/2026 | 30/9/2026 | NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two packets therefore drives the XOR loop… | |
| Pendiente de análisis | Alta (8.3) | 0.21% | — | Netx SecureAI | 29/9/2026 | 29/9/2026 | When NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent on an active session is wiped after it has been handed to TCP. By then the TCP layer owns the packet chain and may already have released it to the packet pool. The wipe therefore writes zeros into packets that are free or in use by another… | |
| Pendiente de análisis | Media (6.3) | 0.16% | — | Expresslogic Netx Secure TLSAI | 29/9/2026 | 29/9/2026 | NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is… | |
| Pendiente de análisis | Alta (7.5) | 0.17% | — | Microsoft Netx SecureAI | 29/9/2026 | 30/9/2026 | The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake. The function reads the one-byte… | |
| Pendiente de análisis | Alta (7.5) | 0.24% | — | Azure Netx SecureAI | 29/9/2026 | 30/9/2026 | Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both are reached from a TLS or DTLS client connecting to a malicious or malformed… | |
| Pendiente de análisis | Media (6.9) | 0.25% | — | Expresslogic Netx DUOAI | 29/9/2026 | 29/9/2026 | A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 1984). When the opcode is NX_TFTP_CODE_ERROR the message string is copied with a loop whose… | |
| Pendiente de análisis | Media (5.3) | 0.15% | — | Expresslogic Netx DUOAI | 29/9/2026 | 29/9/2026 | A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a kilobyte past the end of the received message. The option walk keeps a pointer and an offset in step, and the only bound check uses the offset: ```c /* addons/dhcp/nxd_dhcp_client.c:7538, 7572 */ while (i < length - 1)… | |
| Pendiente de análisis | Media (6.3) | 0.21% | — | Netx SecureAI | 29/9/2026 | 29/9/2026 | Predictable DTLS HelloVerifyRequest Cookie in NetX Secure | |
| Pendiente de análisis | Alta (8.7) | 0.31% | — | Expresslogic Netx DUOAI | 29/9/2026 | 29/9/2026 | hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNMP packet with a multibyte OID length larger than the available buffer, causing the… | |
| Pendiente de análisis | Alta (8.7) | 0.25% | — | Microsoft NetxAI | 29/9/2026 | 29/9/2026 | An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests that carry a Session header the parser cannot convert. The Session branch returns the raw NetX error code instead of an RTSP status code: ```c /* addons/rtsp/nx_rtsp_server.c:2754 */ if (status) ``` Every other branch of… | |
| Pendiente de análisis | Alta (7.1) | 0.15% | — | Expresslogic Netx DUOAI | 29/9/2026 | 29/9/2026 | Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table stores each name in a slot rounded up to a multiple of four: ```c /* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */ ... len = *((USHORT*)(p - 2)); /* slot size, not string length */ if ((len… | |
| Pendiente de análisis | Alta (8.8) | 0.31% | — | NetxAIFilexAI | 29/9/2026 | 29/9/2026 | The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than four bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper bound, in particular not against the protocol maximum of 4 + NX_TFTP_FILE_TRANSFER_MAX. Two things follow from that one missing check, both… | |
| Analizada | Alta (7.5) | 0.46% | — | Eclipse Threadx Netx DUO | 19/6/2026 | 2/7/2026 | The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file was never successfully opened. Multiple error branches jump to the shared cleanup… | |
| Analizada | Alta (8.7) | 0.40% | — | Eclipse Threadx Netx DUO | 27/1/2026 | 17/6/2026 | A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network packet of "Packet Too Big" with more than 15 different source address can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability. | |
| Analizada | Media (6.3) | 0.41% | — | Eclipse Threadx Netx DUO | 20/10/2025 | 17/6/2026 | In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked index extracting the server DUID from the server reply. With a crafted packet, an attacker could cause an out of memory read. | |
| Analizada | Alta (8.8) | 0.61% | — | Eclipse Threadx Netx DUO | 17/10/2025 | 17/6/2026 | In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was missing bounds verification. A crafted server response could cause undefined behavior. | |
| Analizada | Media (6.9) | 0.41% | — | Eclipse Threadx Netx DUO | 17/10/2025 | 17/6/2026 | In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_icmpv6_validate_options() when handling a packet with ICMP6 options. | |
| Analizada | Media (6.3) | 0.46% | — | Eclipse Threadx Netx DUO | 17/10/2025 | 17/6/2026 | In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an out-of-bound read by a crafted SNMPv3 security parameters. | |
| Analizada | Media (6.9) | 0.31% | — | Eclipse Threadx Netx DUO | 17/10/2025 | 17/6/2026 | In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() when handling unicast DHCP messages that could cause corruption of 4 bytes of memory. | |
| Analizada | Media (6.9) | 0.33% | — | Eclipse Threadx Netx DUO | 17/10/2025 | 17/6/2026 | In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_option_process() when processing an IPv4 packet with the timestamp option. | |
| Analizada | Media (6.9) | 0.37% | — | Eclipse Threadx Netx DUO | 16/10/2025 | 17/6/2026 | In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ip_packet_receive() function when received an Ethernet with type set as IP but no IP data. | |
| Analizada | Media (6.9) | 0.37% | — | Eclipse Threadx Netx DUO | 16/10/2025 | 17/6/2026 | In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() function when received an Ethernet frame with less than 4 bytes of IP packet. | |
| Analizada | Media (6.9) | 0.33% | — | Eclipse Threadx Netx DUO | 16/10/2025 | 17/6/2026 | In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_secure_tls_proc_clienthello_supported_versions_extension() in the extension version field. | |
| Analizada | Media (6.9) | 0.25% | — | Eclipse Threadx Netx DUO | 15/10/2025 | 17/6/2026 | In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check resulting it out by two out of bound read. |