« Back to list

Contiki-ng

Contiki-ng: vulnerabilities and CVEs

Contiki-ng has 45 published vulnerabilities, 3 of them in the last 12 months. 21 are rated critical and 0 are listed by CISA as actively exploited.

CVEs45
Last 12 months3
Critical21
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-5856High (7.1)0.29%—Aug 6, 2026
Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no packet-boundary check, and the caller in newdata() invokes it in a loop iterating nquestions times from…
CVE-2026-5855High (8.7)0.72%—Aug 6, 2026
Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in…
CVE-2026-5857Critical (9.2)0.92%—Aug 6, 2026
Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set.…
CVE-2024-47181High (7.5)0.58%—Nov 27, 2024
Contiki-NG is an open-source, cross-platform operating system for IoT devices. An unaligned memory access can be triggered in the two RPL implementations of the Contiki-NG operating system. The problem can occur when…
CVE-2024-41126Critical (9.6)0.29%—Nov 27, 2024
Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be triggered when sending a packet to a device running the Contiki-NG operating system with SNMP…
CVE-2024-41125Critical (9.6)0.29%—Nov 27, 2024
Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be triggered when sending a packet to a device running the Contiki-NG operating system with SNMP…
CVE-2023-29001High (8.7)0.56%—Nov 27, 2024
Contiki-NG is an open-source, cross-platform operating system for IoT devices. The Contiki-NG operating system processes source routing headers (SRH) in its two alternative RPL protocol implementations. The IPv6…
CVE-2023-50927High (7.5)0.51%—Feb 14, 2024
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An attacker can trigger out-of-bounds reads in the RPL-Lite implementation of the RPL protocol in the Contiki-NG operating…
CVE-2023-50926High (7.5)0.53%—Feb 14, 2024
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can be caused by an incoming DIO message when using the RPL-Lite implementation in the Contiki-NG…
CVE-2023-48229High (7.6)0.39%—Feb 14, 2024
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds write exists in the driver for IEEE 802.15.4 radios on nRF platforms in the Contiki-NG operating system.…
CVE-2020-27634Critical (9.1)1.7%—Oct 10, 2023
In Contiki 4.5, TCP ISNs are improperly random.
CVE-2023-37459Medium (5.3)0.46%—Sep 15, 2023
Contiki-NG is an operating system for internet-of-things devices. In versions 4.9 and prior, when a packet is received, the Contiki-NG network stack attempts to start the periodic TCP timer if it is a TCP packet with…
CVE-2023-37281Medium (5.3)0.46%—Sep 15, 2023
Contiki-NG is an operating system for internet-of-things devices. In versions 4.9 and prior, when processing the various IPv6 header fields during IPHC header decompression, Contiki-NG confirms the received packet…
CVE-2023-34101Critical (9.1)0.51%—Jun 14, 2023
Contiki-NG is an operating system for internet of things devices. In version 4.8 and prior, when processing ICMP DAO packets in the `dao_input_storing` function, the Contiki-NG OS does not verify that the packet buffer…
CVE-2023-34100Medium (6.5)0.44%—Jun 9, 2023
Contiki-NG is an open-source, cross-platform operating system for IoT devices. When reading the TCP MSS option value from an incoming packet, the Contiki-NG OS does not verify that certain buffer indices to read from…
CVE-2023-31129Critical (9.8)0.64%—May 8, 2023
The Contiki-NG operating system versions 4.8 and prior can be triggered to dereference a NULL pointer in the message handling code for IPv6 router solicitiations. Contiki-NG contains an implementation of IPv6 Neighbor…
CVE-2023-30546High (7.5)0.64%—Apr 26, 2023
Contiki-NG is an operating system for Internet of Things devices. An off-by-one error can be triggered in the Antelope database management system in the Contiki-NG operating system in versions 4.8 and prior. The problem…
CVE-2023-28116Critical (9.8)0.69%—Mar 17, 2023
Contiki-NG is an open-source, cross-platform operating system for internet of things (IoT) devices. In versions 4.8 and prior, an out-of-bounds write can occur in the BLE L2CAP module of the Contiki-NG operating system.…
CVE-2023-23609High (7.4)0.35%—Jan 26, 2023
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to and including 4.8 are vulnerable to an out-of-bounds write that can occur in the BLE-L2CAP module. The…
CVE-2022-41972Medium (6.5)0.21%—Dec 16, 2022
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to 4.9 contain a NULL Pointer Dereference in BLE L2CAP module. The Contiki-NG operating system for IoT…
CVE-2022-41873Medium (5.4)0.26%—Nov 11, 2022
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to 4.9 are vulnerable to an Out-of-bounds read. While processing the L2CAP protocol, the Bluetooth Low Energy…
CVE-2022-36054High (8.8)0.76%—Sep 1, 2022
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The 6LoWPAN implementation in the Contiki-NG operating system (file os/net/ipv6/sicslowpan.c) contains an input function…
CVE-2022-36053High (8.8)0.61%—Sep 1, 2022
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The low-power IPv6 network stack of Contiki-NG has a buffer module (os/net/ipv6/uipbuf.c) that processes IPv6 extension…
CVE-2022-36052High (8.8)0.64%—Sep 1, 2022
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The 6LoWPAN implementation in Contiki-NG may cast a UDP header structure at a certain offset in a packet buffer. The code…
CVE-2022-35927Critical (9.8)2.1%—Aug 4, 2022
Contiki-NG is an open-source, cross-platform operating system for IoT devices. In the RPL-Classic routing protocol implementation in the Contiki-NG operating system, an incoming DODAG Information Option (DIO) control…
CVE-2022-35926High (7.5)1.2%—Aug 4, 2022
Contiki-NG is an open-source, cross-platform operating system for IoT devices. Because of insufficient validation of IPv6 neighbor discovery options in Contiki-NG, attackers can send neighbor solicitation packets that…
CVE-2021-32771High (8.1)1.3%—Aug 4, 2022
Contiki-NG is an open-source, cross-platform operating system for IoT devices. In affected versions it is possible to cause a buffer overflow when copying an IPv6 address prefix in the RPL-Classic implementation in…
CVE-2020-12140High (8.8)0.95%—Dec 7, 2021
A buffer overflow in os/net/mac/ble/ble-l2cap.c in the BLE stack in Contiki-NG 4.4 and earlier allows an attacker to execute arbitrary code via malicious L2CAP frames.
CVE-2020-12141Critical (9.1)1.6%—Oct 19, 2021
An out-of-bounds read in the SNMP stack in Contiki-NG 4.4 and earlier allows an attacker to cause a denial of service and potentially disclose information via crafted SNMP packets to snmp_ber_decode_string_len_buffer in…
CVE-2021-21410Critical (9.1)1.2%—Jun 18, 2021
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can be triggered by 6LoWPAN packets sent to devices running Contiki-NG 4.6 and prior. The IPv6 header…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application4
  2. T1210 Exploitation of Remote Services3
  3. T1005 Data from Local System2
  4. T1499.004 Application or System Exploitation2
  5. T1059 Command and Scripting Interpreter1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Contiki-ng