CVE-2026-22211 is a global buffer overflow vulnerability in TinyOS versions up to 2.1.2, specifically within the printfUART function of its ZigBee/IEEE 802.15.4 networking stack. This flaw allows an attacker to cause denial of service, unintended behavior, or information disclosure by providing a string longer than the fixed-size buffer, leading to memory corruption. The CVSS score of 5.1 (Medium) indicates a local attack vector with low complexity, but the exploitability is currently unknown. There is no public exploit code available, nor is there any significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| TinyOS | TinyOS | >= 0, <= 2.1.2CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.