CVE-2020-25112 is a critical vulnerability affecting the IPv6 stack in Contiki OS through version 3.0, stemming from inconsistent checks for IPv6 header extension lengths. This flaw allows for Denial-of-Service and potential Remote Code Execution through specially crafted ICMPv6 echo packets, carrying a CVSS score of 9.8. Despite its high severity and potential for remote exploitation with low complexity, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has not been added to CISA's KEV catalog. Furthermore, the vulnerability has garnered minimal community discussion or media coverage, suggesting a low profile despite its critical impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.0CPE matchmatch criteria | cpe:2.3:o:contiki-os:contiki-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.