Impact
The DHCP client in Eclipse ThreadX/NetX Duo incorrectly walks through TLV options, allowing a malicious OFFER to bypass bounds checks and read past the end of a message; this heap-buffer-overflow can corrupt memory used for interface configuration and may enable arbitrary code execution on the affected device.
Affected Systems
The vulnerability affects the Eclipse ThreadX/NetX Duo product family; specific version information is not supplied in the advisory, so all releases of NetX Duo that include the uncovered code path are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity weakness, and the lack of an EPSS entry shows no known exploitation probability yet; the vulnerability is not listed in CISA’s KEV catalog. The attack vector is local – an attacker who can send crafted DHCP traffic on the same LAN can trigger the overflow at boot time, potentially compromising the device before it fully starts. An attacker could alter configuration, crash the client, or execute arbitrary code depending on the memory state of the process.
OpenCVE Enrichment