Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Contiki Os

First CVE: May 28, 2017Active for: 9 yearsTotal CVEs: 44

Contiki OS is a lightweight operating system designed for embedded systems and Internet-of-Things devices with severely constrained resources, and the vulnerability disclosures associated with it reflect the challenges of securing networked firmware in that domain. The vendor's footprint remains modestly represented in the broader vulnerability landscape, though its prominence within the IoT and embedded systems ecosystem is more pronounced given the widespread deployment of Contiki-based devices in sensor networks and low-power wireless applications. The observed vulnerability patterns do not cluster around a single dominant weakness class, reflecting the diverse attack surface spanning network protocols, memory management, and device-specific configurations that characterize an OS serving heterogeneous hardware platforms. Defenders operating Contiki-based deployments should prioritize inventory of affected devices and firmware versions, as patching embedded systems often requires coordination across hardware vendors and deployment contexts rather than straightforward updates. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
3.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Contiki Os over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 28, 2017
9 years ago
Most Recent CVE
Sep 5, 2021
1,784 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-24336CRITICAL
An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answers in ip64-dns64.c doesn't verify whether the address in the
Dec 11, 20209.862NONO
CVE-2020-25112CRITICAL
An issue was discovered in the IPv6 stack in Contiki through 3.0. There are inconsistent checks for IPv6 header extension lengths. This leads to Denial-of-Service and potential Rem
Dec 11, 20209.843NONO
CVE-2020-25111CRITICAL
An issue was discovered in the IPv6 stack in Contiki through 3.0. There is an insufficient check for the IPv6 header length. This leads to Denial-of-Service and potential Remote Co
Dec 11, 20209.840NONO
CVE-2020-17438CRITICAL
An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that reassembles fragmented packets fails to properly validate the total length of an incomi
Dec 11, 20209.837NONO
CVE-2019-8359CRITICAL
An issue was discovered in Contiki-NG through 4.3 and Contiki through 3.0. An out of bounds write is present in the data section during 6LoWPAN fragment re-assembly in the face of
Apr 23, 20209.829NONO
CVE-2020-17437HIGH
An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, t
Dec 11, 20208.226NONO
CVE-2021-40523HIGH
In Contiki 3.0, Telnet option negotiation is mishandled. During negotiation between a server and a client, the server may fail to give the WILL/WONT or DO/DONT response for DO and
Sep 5, 20217.525NONO
CVE-2020-24334HIGH
The code that processes DNS responses in uIP through 1.0, as used in Contiki and Contiki-NG, does not check whether the number of responses specified in the DNS packet header corre
Dec 11, 20208.225NONO
CVE-2020-17439HIGH
An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets does not validate that the incoming DNS replies match outgo
Dec 11, 20208.325NONO
CVE-2020-13987HIGH
An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_
Dec 11, 20207.525NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
73%
23%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None21 (95.5%)
Unknown0 (0.0%)
Required1 (4.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None22 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Contiki Os.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Contiki Os — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Contiki Os's Products

View all 1 CNAs →

Top CWEs