Contiki Ng is an operating system and software framework purpose-built for resource-constrained embedded systems and Internet of Things devices, featuring a small but broadly deployable codebase centered on the core Contiki Ng platform and its integrated TinyDTLS cryptographic library. The vulnerability exposure reflects the attack surface inherent to low-power wireless and networked embedded environments, where memory constraints and protocol complexity create persistent developmental challenges. Defenders working with IoT deployments and edge-networked devices should monitor this vendor's advisories as part of inventory assessment and long-term device support planning, since embedded systems often remain in service far beyond their initial support windows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Contiki Ng over time
Signals from CVEs in this vendor scope (57 CVEs).
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24336CRITICAL An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answers in ip64-dns64.c doesn't verify whether the address in the | Dec 11, 2020 | 9.8 | 62 | NO | NO |
CVE-2018-1000804CRITICAL contiki-ng version 4 contains a Buffer Overflow vulnerability in AQL (Antelope Query Language) database engine that can result in Attacker can perform Remote Code Execution on devi | Oct 8, 2018 | 9.8 | 34 | NO | NO |
CVE-2018-19417CRITICAL An issue was discovered in the MQTT server in Contiki-NG before 4.2. The function parse_publish_vhdr() that parses MQTT PUBLISH messages with a variable length header uses memcpy t | Nov 21, 2018 | 10.0 | 32 | NO | NO |
CVE-2023-31129CRITICAL The Contiki-NG operating system versions 4.8 and prior can be triggered to dereference a NULL pointer in the message handling code for IPv6 router solicitiations. Contiki-NG contai | May 8, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-28116CRITICAL Contiki-NG is an open-source, cross-platform operating system for internet of things (IoT) devices. In versions 4.8 and prior, an out-of-bounds write can occur in the BLE L2CAP mod | Mar 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2020-14935CRITICAL Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP bulk get request response encoding function. The function parsing the received SNMP request does not ver | Aug 18, 2020 | 9.8 | 30 | NO | NO |
CVE-2024-41125CRITICAL Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be triggered when sending a packet to a device running the Contik | Nov 27, 2024 | 9.6 | 29 | NO | NO |
CVE-2021-42142CRITICAL An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a large epoch number. This vulnerability allows remote attacke | Jan 23, 2024 | 9.8 | 29 | NO | NO |
CVE-2022-35927CRITICAL Contiki-NG is an open-source, cross-platform operating system for IoT devices. In the RPL-Classic routing protocol implementation in the Contiki-NG operating system, an incoming DO | Aug 4, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-21281CRITICAL Contiki-NG is an open-source, cross-platform operating system for internet of things devices. A buffer overflow vulnerability exists in Contiki-NG versions prior to 4.6. After esta | Jun 18, 2021 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (57 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Contiki Ng.
Media articles that mention a CVE ID that affects a product developed by Contiki Ng — matched by CVE ID, not by vendor name.