FreeRTOS-Plus-TCP是FreeRTOS开源的一种适用于 FreeRTOS 的可扩展的开源和线程安全 TCP/IP 堆栈。 FreeRTOS-Plus-TCP V4.2.6之前版本和V4.4.1之前版本存在安全漏洞,该漏洞源于数据包验证不足,可能导致相邻网络参与者通过伪造以太网源MAC地址绕过所有校验和及最小大小验证。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AWS | FreeRTOS-Plus-TCP | 4.0.0< 4.2.6 |
affected |
4.3.0< 4.4.1 |
affected | ||
4.2.6 |
unaffected | ||
4.4.1 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | FreeRTOS-Plus-TCP | 4.0.0 ~ 4.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7424 | 8.1 HIGH | Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP |
| CVE-2026-7426 | 8.1 HIGH | Out-of-Bounds Write via Unsanitized Prefix Length in Router Advertisement Processing in Fr |
| CVE-2026-7425 | 6.5 MEDIUM | Out-of-Bounds Read in Router Advertisement Option Parser in FreeRTOS-Plus-TCP |
| CVE-2026-7423 | 5.3 MEDIUM | Integer Underflow in ICMP Echo Reply Processing in FreeRTOS-Plus-TCP |
No comments yet