OpenThread is a low-power mesh-networking stack maintained by Google, with vulnerabilities concentrating in its wpantund daemon and reflecting the memory-management and boundary-checking complexities of embedded network protocol code. The observed weakness classes include memory-lifetime issues and out-of-bounds writes, which are characteristic of C-based network implementations handling untrusted radio input. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openthread over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33889MEDIUM OpenThread wpantund through 2021-07-02 has a stack-based Buffer Overflow because of an inconsistency in the integer data type for metric_len. | Jul 2, 2021 | 6.8 | 22 | NO | NO |
CVE-2020-8916MEDIUM A memory leak in Openthread's wpantund versions up to commit 0e5d1601febb869f583e944785e5685c6c747be7, when used in an environment where wpanctl is directly interfacing with the co | Jul 7, 2020 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openthread.
Media articles that mention a CVE ID that affects a product developed by Openthread — matched by CVE ID, not by vendor name.