Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Contiki Ng Project

First CVE: —Active for: N/ATotal CVEs: 57

Contiki Ng Project maintains a lightweight operating system and runtime environment designed for low-power embedded and IoT devices, with the vulnerability footprint centered on the Contiki NG platform itself. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
55
Total CVEs
Bottom 1%
3.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Contiki Ng Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 7, 2018
7 years ago
Most Recent CVE
Nov 27, 2024
608 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (55 CVEs).

55 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-24336CRITICAL
An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answers in ip64-dns64.c doesn't verify whether the address in the
Dec 11, 20209.862NONO
CVE-2018-1000804CRITICAL
contiki-ng version 4 contains a Buffer Overflow vulnerability in AQL (Antelope Query Language) database engine that can result in Attacker can perform Remote Code Execution on devi
Oct 8, 20189.834NONO
CVE-2018-19417CRITICAL
An issue was discovered in the MQTT server in Contiki-NG before 4.2. The function parse_publish_vhdr() that parses MQTT PUBLISH messages with a variable length header uses memcpy t
Nov 21, 201810.032NONO
CVE-2023-31129CRITICAL
The Contiki-NG operating system versions 4.8 and prior can be triggered to dereference a NULL pointer in the message handling code for IPv6 router solicitiations. Contiki-NG contai
May 8, 20239.831NONO
CVE-2023-28116CRITICAL
Contiki-NG is an open-source, cross-platform operating system for internet of things (IoT) devices. In versions 4.8 and prior, an out-of-bounds write can occur in the BLE L2CAP mod
Mar 17, 20239.830NONO
CVE-2020-14935CRITICAL
Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP bulk get request response encoding function. The function parsing the received SNMP request does not ver
Aug 18, 20209.830NONO
CVE-2024-41125CRITICAL
Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be triggered when sending a packet to a device running the Contik
Nov 27, 20249.629NONO
CVE-2021-42142CRITICAL
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a large epoch number. This vulnerability allows remote attacke
Jan 23, 20249.829NONO
CVE-2022-35927CRITICAL
Contiki-NG is an open-source, cross-platform operating system for IoT devices. In the RPL-Classic routing protocol implementation in the Contiki-NG operating system, an incoming DO
Aug 4, 20229.829NONO
CVE-2021-21281CRITICAL
Contiki-NG is an open-source, cross-platform operating system for internet of things devices. A buffer overflow vulnerability exists in Contiki-NG versions prior to 4.6. After esta
Jun 18, 20219.829NONO
View all 55 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products55 CVEs
11%
44%
45%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (10.9%)
Network42 (76.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network7 (12.7%)
Attack Complexity
Low52 (94.5%)
High3 (5.5%)
Unknown0 (0.0%)
User Interaction
None55 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low9 (16.4%)
High0 (0.0%)
None46 (83.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (55 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Contiki Ng Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Contiki Ng Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Contiki Ng Project's Products

View all 2 CNAs →

Top CWEs