CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-55080: threadx before 6.4.3 (exclusive); +1 more affected products

CVE-2025-55080. CVSS 3.1 base score 7.1 (HIGH, NVD). EPSS 0.00138 (percentile 0.02718), scored 2026-10-06.

Affected technology

threadx · before 6.4.3 (exclusive)
eclipse

ThreadX · 0 to before 6.4.3
Eclipse Foundation

Description’s affected range: before 6.4.3

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

The source says in Eclipse ThreadX before 6.4.3, when memory protection is enabled, syscall parameters verification wasn't enough, allowing an attacker to obtain an arbitrary memory read/write. Vendor/CNA’s CVSS 4.0 assessment (base score 7.2/10) rates confidentiality and integrity impact as high; availability impact as none.

Published

CWE
CWE-233
CCR priority
28.4 /100 (P4)
CVSS 3.1
7.1 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N · NVD
EPSS
0.00138 · percentile 0.02753 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-55080.html