Chirpstack is a focused open-source LoRaWAN network server and gateway management platform whose vulnerability footprint centers on input-validation weaknesses across components such as the gateway bridge, MQTT forwarder, and core network server. The observed weakness classes reflect the message-handling and protocol-parsing demands of a distributed IoT middleware stack. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chirpstack over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-29862HIGH The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4.2.1 and chirpstack-gateway-bridge before 4.0.11 wrongly accepts certain TCP packets when a connection is not i | Mar 21, 2024 | 7.5 | 22 | NO | NO |
CVE-2020-28349MEDIUM An inaccurate frame deduplication process in ChirpStack Network Server 3.9.0 allows a malicious gateway to perform uplink Denial of Service via malformed frequency attributes in Co | Nov 9, 2020 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chirpstack.
Media articles that mention a CVE ID that affects a product developed by Chirpstack — matched by CVE ID, not by vendor name.