Freertos Plus Tcp
Vendor:
First CVE: Jun 24, 2024 · Active for 2 years
9
Total CVEs
More Total CVEs than 88% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Freertos Plus Tcp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 24, 2024
2 years ago
Most Recent CVE
Apr 29, 2026
90 days ago
CVE Severity & Scoring
Freertos Plus Tcp9 CVEs
67%
33%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network4 (44.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network5 (55.6%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (44.4%)
High0 (0.0%)
None5 (55.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-7424HIGH Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DN | Apr 29, 2026 | 8.1 | 32 | NO | NO |
CVE-2026-7426HIGH Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause m | Apr 29, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-7425MEDIUM Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of se | Apr 29, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-7422MEDIUM Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Eth | Apr 29, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-7423MEDIUM Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial of service (device cras | Apr 29, 2026 | 6.5 | 25 | NO | NO |
CVE-2024-38373HIGH FreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the DNS Response Parser when parsin | Jun 24, 2024 | 8.1 | 25 | NO | NO |
CVE-2025-11617MEDIUM A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths in the p | Oct 10, 2025 | 5.4 | 21 | NO | NO |
CVE-2025-11616MEDIUM A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which are s | Oct 10, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-11618MEDIUM A missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing code can lead to an invalid pointer dereference when receiving a UDP/IPv6 packet with an incorrect IP v | Oct 10, 2025 | 4.3 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Freertos Plus Tcp
Top CWEs
Versions
No cataloged versions.