Connman is a lightweight network connection manager targeting embedded and resource-constrained systems, with its vulnerability footprint centered on a single focused product. The observed weakness class centers on improper input validation, reflecting the parsing demands of network configuration and protocol handling in a minimal connectivity daemon.
The number and severity of CVEs published that impact products developed by Connman over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2321HIGH The loopback plug-in in ConnMan before 0.85 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) host name or (2) domain name in a DHCP reply. | May 18, 2012 | 10.0 | 31 | NO | NO |
CVE-2025-32743CRITICAL In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Truncated) bit is set in a DNS response. This allows attackers to | Apr 10, 2025 | 9.0 | 26 | NO | NO |
CVE-2012-2320HIGH ConnMan before 0.85 does not ensure that netlink messages originate from the kernel, which allows remote attackers to bypass intended access restrictions and cause a denial of serv | May 18, 2012 | 7.8 | 23 | NO | NO |
CVE-2012-2322MEDIUM Integer overflow in the dhcpv6_get_option function in gdhcp/client.c in ConnMan before 0.85 allows remote attackers to cause a denial of service (infinite loop and crash) via an in | May 18, 2012 | 5.0 | 18 | NO | NO |
CVE-2025-32366MEDIUM In ConnMan through 1.44, parse_rr in dnsproxy.c has a memcpy length that depends on an RR RDLENGTH value, i.e., *rdlen=ntohs(rr->rdlen) and memcpy(response+offset,*end,*rdlen) with | Apr 5, 2025 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Connman.
Media articles that mention a CVE ID that affects a product developed by Connman — matched by CVE ID, not by vendor name.