CVE-2026-7422
- EPSS 0.03%
- Veröffentlicht 29.04.2026 19:16:26
- Zuletzt bearbeitet 04.05.2026 13:43:07
Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the device's own registered e...
CVE-2026-7423
- EPSS 0.02%
- Veröffentlicht 29.04.2026 19:16:26
- Zuletzt bearbeitet 04.05.2026 13:35:00
Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial of service (device crash) when outgoing ping support is enabled, because header sizes are sub...
CVE-2026-7424
- EPSS 0.02%
- Veröffentlicht 29.04.2026 19:16:26
- Zuletzt bearbeitet 04.05.2026 13:22:20
Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (pe...
CVE-2026-7426
- EPSS 0.02%
- Veröffentlicht 29.04.2026 18:53:52
- Zuletzt bearbeitet 04.05.2026 13:12:17
Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by sending a crafted Router Advertisement with a pref...
CVE-2026-7425
- EPSS 0.02%
- Veröffentlicht 29.04.2026 18:52:36
- Zuletzt bearbeitet 04.05.2026 13:12:57
Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of service (device crash) by sending a crafted Router Advertisement with a ...
CVE-2025-11618
- EPSS 0.05%
- Veröffentlicht 10.10.2025 17:10:34
- Zuletzt bearbeitet 31.10.2025 18:23:01
A missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing code can lead to an invalid pointer dereference when receiving a UDP/IPv6 packet with an incorrect IP version field in the packet header. This issue only affects application...
CVE-2025-11617
- EPSS 0.06%
- Veröffentlicht 10.10.2025 17:10:30
- Zuletzt bearbeitet 31.10.2025 18:22:57
A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths in the packet header. This issue only affects applications using IPv6. We rec...
CVE-2025-11616
- EPSS 0.06%
- Veröffentlicht 10.10.2025 17:10:27
- Zuletzt bearbeitet 31.10.2025 18:22:59
A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which are smaller than the expected size. These issues only affect applications u...
CVE-2024-38373
- EPSS 0.65%
- Veröffentlicht 24.06.2024 17:15:10
- Zuletzt bearbeitet 21.11.2024 09:25:31
FreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the DNS Response Parser when parsing domain names in a DNS response. A carefully crafted DNS response wit...