Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Contiki Ng

First CVE: Sep 7, 2018Active for: 8 yearsTotal CVEs: 113

Contiki Ng is an operating system and software framework purpose-built for resource-constrained embedded systems and Internet of Things devices, featuring a small but broadly deployable codebase centered on the core Contiki Ng platform and its integrated TinyDTLS cryptographic library. The vulnerability exposure reflects the attack surface inherent to low-power wireless and networked embedded environments, where memory constraints and protocol complexity create persistent developmental challenges. Defenders working with IoT deployments and edge-networked devices should monitor this vendor's advisories as part of inventory assessment and long-term device support planning, since embedded systems often remain in service far beyond their initial support windows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
57
Total CVEs
More Total CVEs than 99% of tracked vendors
3.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 94% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Contiki Ng over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 7, 2018
7 years ago
Most Recent CVE
Nov 27, 2024
606 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (57 CVEs).

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-24336CRITICAL
An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answers in ip64-dns64.c doesn't verify whether the address in the
Dec 11, 20209.862NONO
CVE-2018-1000804CRITICAL
contiki-ng version 4 contains a Buffer Overflow vulnerability in AQL (Antelope Query Language) database engine that can result in Attacker can perform Remote Code Execution on devi
Oct 8, 20189.834NONO
CVE-2018-19417CRITICAL
An issue was discovered in the MQTT server in Contiki-NG before 4.2. The function parse_publish_vhdr() that parses MQTT PUBLISH messages with a variable length header uses memcpy t
Nov 21, 201810.032NONO
CVE-2023-31129CRITICAL
The Contiki-NG operating system versions 4.8 and prior can be triggered to dereference a NULL pointer in the message handling code for IPv6 router solicitiations. Contiki-NG contai
May 8, 20239.831NONO
CVE-2023-28116CRITICAL
Contiki-NG is an open-source, cross-platform operating system for internet of things (IoT) devices. In versions 4.8 and prior, an out-of-bounds write can occur in the BLE L2CAP mod
Mar 17, 20239.830NONO
CVE-2020-14935CRITICAL
Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP bulk get request response encoding function. The function parsing the received SNMP request does not ver
Aug 18, 20209.830NONO
CVE-2024-41125CRITICAL
Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be triggered when sending a packet to a device running the Contik
Nov 27, 20249.629NONO
CVE-2021-42142CRITICAL
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a large epoch number. This vulnerability allows remote attacke
Jan 23, 20249.829NONO
CVE-2022-35927CRITICAL
Contiki-NG is an open-source, cross-platform operating system for IoT devices. In the RPL-Classic routing protocol implementation in the Contiki-NG operating system, an incoming DO
Aug 4, 20229.829NONO
CVE-2021-21281CRITICAL
Contiki-NG is an open-source, cross-platform operating system for internet of things devices. A buffer overflow vulnerability exists in Contiki-NG versions prior to 4.6. After esta
Jun 18, 20219.829NONO
View all 57 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products57 CVEs
11%
46%
44%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (10.5%)
Network44 (77.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network7 (12.3%)
Attack Complexity
Low54 (94.7%)
High3 (5.3%)
Unknown0 (0.0%)
User Interaction
None57 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low9 (15.8%)
High0 (0.0%)
None48 (84.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (57 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Contiki Ng.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Contiki Ng — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Contiki Ng's Products

View all 2 CNAs →

Top CWEs