CVE-2026-5857
- EPSS 0.54%
- Veröffentlicht 06.08.2026 22:18:10
- Zuletzt bearbeitet 24.09.2026 20:06:30
Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tcp_i...
CVE-2026-5856
- EPSS 0.25%
- Veröffentlicht 06.08.2026 22:18:10
- Zuletzt bearbeitet 16.09.2026 20:21:01
Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no packet-boundary check, and the caller in newdata() invokes it in a loop iterating nquestions times from the attacker-controlled DNS he...
CVE-2026-5855
- EPSS 0.54%
- Veröffentlicht 06.08.2026 22:18:10
- Zuletzt bearbeitet 16.09.2026 20:21:01
Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterates while there...
CVE-2024-47181
- EPSS 0.56%
- Veröffentlicht 27.11.2024 19:15:33
- Zuletzt bearbeitet 10.04.2025 14:49:56
Contiki-NG is an open-source, cross-platform operating system for IoT devices. An unaligned memory access can be triggered in the two RPL implementations of the Contiki-NG operating system. The problem can occur when either one of these RPL implement...
CVE-2024-41126
- EPSS 0.29%
- Veröffentlicht 27.11.2024 19:15:33
- Zuletzt bearbeitet 10.04.2025 14:54:59
Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be triggered when sending a packet to a device running the Contiki-NG operating system with SNMP enabled. The SNMP module is disabled i...
CVE-2024-41125
- EPSS 0.29%
- Veröffentlicht 27.11.2024 19:15:32
- Zuletzt bearbeitet 10.04.2025 14:55:43
Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be triggered when sending a packet to a device running the Contiki-NG operating system with SNMP enabled. The SNMP module is disabled i...
CVE-2023-29001
- EPSS 0.54%
- Veröffentlicht 27.11.2024 19:15:31
- Zuletzt bearbeitet 10.04.2025 14:58:31
Contiki-NG is an open-source, cross-platform operating system for IoT devices. The Contiki-NG operating system processes source routing headers (SRH) in its two alternative RPL protocol implementations. The IPv6 implementation uses the results of thi...
CVE-2023-50927
- EPSS 0.51%
- Veröffentlicht 14.02.2024 20:15:45
- Zuletzt bearbeitet 07.01.2025 14:53:39
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An attacker can trigger out-of-bounds reads in the RPL-Lite implementation of the RPL protocol in the Contiki-NG operating system. This vulnerability is ca...
CVE-2023-50926
- EPSS 0.53%
- Veröffentlicht 14.02.2024 20:15:45
- Zuletzt bearbeitet 06.01.2025 15:30:54
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can be caused by an incoming DIO message when using the RPL-Lite implementation in the Contiki-NG operating system. More specifically...
CVE-2023-48229
- EPSS 0.39%
- Veröffentlicht 14.02.2024 19:15:08
- Zuletzt bearbeitet 06.01.2025 15:28:46
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds write exists in the driver for IEEE 802.15.4 radios on nRF platforms in the Contiki-NG operating system. The problem is triggered when par...