Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

contiki-ng — Vulnerabilities & Security Advisories 32

All 32 CVE vulnerabilities found in contiki-ng, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the Contiki-NG operating system, focusing on general weakness types and security tags associated with the project. It collects a comprehensive list of reported security issues affecting Contiki-NG, encompassing remote code execution flaws, buffer overflow vulnerabilities, permission bypasses, and denial-of-service conditions. The data covers publicly disclosed vulnerabilities from 2019 through the present, ensuring that both historical context and recent findings are readily accessible for security professionals and developers. By centralizing these records, the page allows users to track vendor advisories and independent disclosures related to this specific real-time operating system. Readers can gain a deeper understanding of common weakness classes that frequently impact embedded and Internet of Things environments running Contiki-NG. Additionally, the resource provides a clear view of the product's vulnerability history, enabling stakeholders to assess the current security posture and identify recurring patterns in code quality or design flaws. This structured approach facilitates better risk management and informed decision-making when deploying or maintaining Contiki-NG in production environments. The information is organized to support quick lookup and detailed analysis without overwhelming the user with unnecessary noise. It serves as a critical reference for anyone involved in the secure development, auditing, or maintenance of Contiki-NG based systems. Whether you are a developer patching known issues or a security researcher analyzing threat landscapes, this aggregation offers a reliable foundation for understanding the security challenges specific to this platform. All entries are curated to provide accurate, actionable insights into the evolving threat landscape surrounding Contiki-NG.

Vendor: contiki-ng

CVE ID Title CVSS Severity Published
CVE-2026-5857 Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persistent State Between TCP Segments CWE-787 8.1 High 2026-08-06
CVE-2026-5856 Contiki-NG DNS/mDNS Resolver Out-of-Bounds Read via Unchecked skip_name Traversal Before Transaction-ID Validation CWE-125 7.1 High 2026-08-06
CVE-2026-5855 Contiki-NG LwM2M TLV Parser Out-of-Bounds Read via Unchecked Buffer Length in lwm2m_tlv_read CWE-125 7.5 High 2026-08-06
CVE-2023-29001 Uncontrolled recursion due to insufficient validation of the IPv6 source routing header in Contiki-NG CWE-674 7.5AI High AI 2024-11-27
CVE-2024-41125 Out-of-bounds read in SNMP when decoding a string in Contiki-NG CWE-125 8.4 High 2024-11-27
CVE-2024-41126 Out-of-bounds read when decoding SNMP messages in Contiki-NG CWE-125 8.4 High 2024-11-27
CVE-2024-47181 Unaligned memory access in RPL option processing in Contiki-NG CWE-704 7.5 High 2024-11-27
CVE-2023-50926 Unvalidated DIO prefix info length in RPL-Lite in Contiki-NG CWE-125 7.5 High 2024-02-14
CVE-2023-50927 Insufficient boundary checks for DIO and DAO messages in RPL-Lite in Contiki-NG CWE-125 8.6 High 2024-02-14
CVE-2023-48229 Out-of-bounds write in the radio driver for Contiki-NG nRF platforms CWE-787 7.0 High 2024-02-14
CVE-2023-37459 Out-of-bounds read when processing a received IPv6 packet CWE-125 5.3 Medium 2023-09-15
CVE-2023-37281 Out-of-bounds read during IPHC address decompression CWE-125 5.3 Medium 2023-09-15
CVE-2023-34101 Contiki-NG vulnerable to out-of-bounds read when processing ICMP DAO input CWE-125 7.3 High 2023-06-14
CVE-2023-34100 Out-of-Bounds Read in contiki-ng CWE-125 7.3 High 2023-06-09
CVE-2023-31129 Contiki-NG missing NULL pointer check in IPv6 neighbor discovery CWE-476 7.5 High 2023-05-08
CVE-2023-30546 Contiki-NG has off-by-one error in Antelope DBMS CWE-125 9.8 Critical 2023-04-26
CVE-2023-28116 Buffer overflow in L2CAP due to misconfigured MTU CWE-120 8.1 High 2023-03-17
CVE-2023-23609 contiki-ng BLE-L2CAP contains Improper size validation of L2CAP frames CWE-787 8.2 High 2023-01-25
CVE-2022-41972 Contiki-NG contains NULL Pointer Dereference in BLE L2CAP module CWE-476 2.9 Low 2022-12-16
CVE-2022-41873 Out-of-bounds read and write in BLE L2CAP module CWE-125 4.2 Medium 2022-11-11
CVE-2022-36054 Out-of-bounds write when decompressing 6LoWPAN payload in Contiki-NG CWE-787 6.8 Medium 2022-09-01
CVE-2022-36052 Out-of-bounds read when decompressing UDP header CWE-125 5.9 Medium 2022-09-01
CVE-2022-36053 Out-of-bounds read in the uIP buffer module CWE-125 5.9 Medium 2022-09-01
CVE-2022-35927 Unverified DIO prefix info lengths in RPL-Classic in Contiki-NG CWE-120 8.1 High 2022-08-04
CVE-2022-35926 Out-of-bounds read in IPv6 neighbor solicitation in Contiki-NG CWE-125 5.9 Medium 2022-08-04
CVE-2021-32771 Buffer overflow in contiki-ng CWE-120 8.1 High 2022-08-04
CVE-2021-21410 Out-of-bounds read in the 6LoWPAN implementation CWE-125 8.2 High 2021-06-18
CVE-2021-21257 Out-of-bounds write in RPL-Classic and RPL-Lite CWE-787 8.2 High 2021-06-18
CVE-2021-21279 Infinite loop in IPv6 neighbor solicitation processing CWE-835 7.5 High 2021-06-18
CVE-2021-21280 Out-of-bounds write when processing 6LoWPAN extension headers CWE-787 8.6 High 2021-06-18

All 32 known CVE vulnerabilities affecting contiki-ng with full Chinese analysis, references, and POCs where available.