Contiki-ng
This hub aggregates every CVE we track for Contiki-ng, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
51
CVEs tracked
11
Critical
31
High
0
In CISA KEV
Severity distribution
HIGH31CRITICAL11MEDIUM8LOW1
Monthly trend
0
0
4
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
3
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Contiki-ng.
- CVE-2026-5857Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persistent State Between TCP Segments8.1
- CVE-2026-5856Contiki-NG DNS/mDNS Resolver Out-of-Bounds Read via Unchecked skip_name Traversal Before Transaction-ID Validation7.1
- CVE-2026-5855Contiki-NG LwM2M TLV Parser Out-of-Bounds Read via Unchecked Buffer Length in lwm2m_tlv_read7.5
- CVE-2023-29001Uncontrolled recursion due to insufficient validation of the IPv6 source routing header in Contiki-NG7.5
- CVE-2024-41125Out-of-bounds read in SNMP when decoding a string in Contiki-NG8.3
- CVE-2024-41126Out-of-bounds read when decoding SNMP messages in Contiki-NG8.3
- CVE-2024-47181Unaligned memory access in RPL option processing in Contiki-NG7.5
- CVE-2023-50926Unvalidated DIO prefix info length in RPL-Lite in Contiki-NG7.5
- CVE-2023-50927Insufficient boundary checks for DIO and DAO messages in RPL-Lite in Contiki-NG8.6
- CVE-2023-48229Out-of-bounds write in the radio driver for Contiki-NG nRF platforms7.0
- CVE-2020-27634In Contiki 4.5, TCP ISNs are improperly random.9.1
- CVE-2023-37459Out-of-bounds read when processing a received IPv6 packet5.3
- CVE-2023-37281Out-of-bounds read during IPHC address decompression5.3
- CVE-2023-34101Contiki-NG vulnerable to out-of-bounds read when processing ICMP DAO input7.3
- CVE-2023-34100Out-of-Bounds Read in contiki-ng7.3
Product normalization is registry-driven with AI assist and human review. How it works