Riot-os
Riot-os Riot: vulnerabilidades y CVE
Riot-os Riot tiene 40 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 13 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE40
Últimos 12 meses6
Críticas13
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-27703 | Crítica (9.8) | 0.60% | — | 11 mar 2026 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. In 2026.01 and earlier, the default handler for the… |
| CVE-2026-25139 | Alta (8.7) | 0.56% | — | 4 feb 2026 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. In version 2025.10 and prior, multiple out-of-bounds read allow… |
| CVE-2026-22214 | Media (6.8) | 0.45% | — | 12 ene 2026 | RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos utility due to missing bounds checking when processing incoming serial frame data. The… |
| CVE-2026-22213 | Baja (2.4) | 0.39% | — | 12 ene 2026 | RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapslip6 utility. The vulnerability is caused by unsafe string concatenation in the devopen() function,… |
| CVE-2025-66647 | Baja (1.7) | 0.97% | — | 17 dic 2025 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. A vulnerability was discovered in the IPv6 fragmentation… |
| CVE-2025-66646 | Baja (1.7) | 0.68% | — | 17 dic 2025 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. A vulnerability was discovered in the IPv6 fragmentation… |
| CVE-2025-53888 | Media (6.6) | 0.74% | — | 18 jul 2025 | RIOT-OS, an operating system that supports Internet of Things devices, has an ineffective size check implemented with `assert()` can lead to buffer overflow in versions up to and including 2025.04. Assertions are… |
| CVE-2024-53980 | Media (6.9) | 0.76% | — | 29 nov 2024 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. A malicious actor can send a IEEE 802.15.4 packet with spoofed… |
| CVE-2024-52802 | Alta (7.5) | 0.76% | — | 22 nov 2024 | RIOT is an operating system for internet of things (IoT) devices. In version 2024.04 and prior, the function `_parse_advertise`, located in `/sys/net/application_layer/dhcpv6/client.c`, has no minimum header length… |
| CVE-2024-32018 | Crítica (9) | 1.5% | — | 1 may 2024 | RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit and 32-bit microcontrollers. Most codebases define assertion macros which compile to a no-op on… |
| CVE-2024-32017 | Crítica (9) | 1.5% | — | 1 may 2024 | RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit and 32-bit microcontrollers. The size check in the `gcoap_dns_server_proxy_get()` function contains… |
| CVE-2024-31225 | Crítica (9) | 1.3% | — | 1 may 2024 | RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit and 32-bit microcontrollers. The `_on_rd_init()` function does not implement a size check before… |
| CVE-2023-33975 | Crítica (9.8) | 1.5% | — | 30 may 2023 | RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. In version 2023.01 and prior, an attacker can send a crafted frame to the device… |
| CVE-2023-33974 | Media (5.9) | 0.71% | — | 30 may 2023 | RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. In versions 2023.01 and prior, an attacker can send multiple crafted frames to the… |
| CVE-2023-33973 | Alta (7.5) | 0.96% | — | 30 may 2023 | RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. In versions 2023.01 and prior, an attacker can send a crafted frame which is… |
| CVE-2023-24826 | Alta (7.5) | 0.83% | — | 30 may 2023 | RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2023.04, an attacker can send crafted frames to the device to… |
| CVE-2023-24825 | Alta (7.5) | 0.96% | — | 30 may 2023 | RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2023.04, an attacker can send a crafted frame to the device to… |
| CVE-2023-24817 | Alta (7.5) | 0.64% | — | 30 may 2023 | RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2023.04, an attacker can send a crafted frame to the device… |
| CVE-2023-24823 | Crítica (9.8) | 0.98% | — | 24 abr 2023 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device… |
| CVE-2023-24822 | Alta (7.5) | 0.86% | — | 24 abr 2023 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device… |
| CVE-2023-24821 | Alta (7.5) | 0.86% | — | 24 abr 2023 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device… |
| CVE-2023-24820 | Alta (7.5) | 0.86% | — | 24 abr 2023 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. An attacker can send a crafted frame to the device resulting in a large out of… |
| CVE-2023-24819 | Crítica (9.8) | 0.98% | — | 24 abr 2023 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device… |
| CVE-2023-24818 | Alta (7.5) | 1.2% | — | 24 abr 2023 | RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device… |
| CVE-2021-27427 | Crítica (9.8) | 1.7% | — | 3 may 2022 | RIOT OS version 2020.01.1 is vulnerable to integer wrap-around in its implementation of calloc function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code… |
| CVE-2021-41061 | Media (5.5) | 0.21% | — | 15 sept 2021 | In RIOT-OS 2021.01, nonce reuse in 802.15.4 encryption in the ieee820154_security component allows attackers to break encryption by triggering reboots. |
| CVE-2021-31664 | Alta (7.5) | 1.3% | — | 18 jun 2021 | RIOT-OS 2021.01 before commit 44741ff99f7a71df45420635b238b9c22093647a contains a buffer overflow which could allow attackers to obtain sensitive information. |
| CVE-2021-31663 | Alta (7.5) | 1.6% | — | 18 jun 2021 | RIOT-OS 2021.01 before commit bc59d60be60dfc0a05def57d74985371e4f22d79 contains a buffer overflow which could allow attackers to obtain sensitive information. |
| CVE-2021-31662 | Alta (7.5) | 1.3% | — | 18 jun 2021 | RIOT-OS 2021.01 before commit 07f1254d8537497552e7dce80364aaead9266bbe contains a buffer overflow which could allow attackers to obtain sensitive information. |
| CVE-2021-31661 | Alta (7.5) | 1.3% | — | 18 jun 2021 | RIOT-OS 2021.01 before commit 609c9ada34da5546cffb632a98b7ba157c112658 contains a buffer overflow that could allow attackers to obtain sensitive information. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.