Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pengutronix

First CVE: Sep 5, 2019Active for: 7 yearsTotal CVEs: 15
41.3
VTI Score
High

Pengutronix develops critical embedded-system bootloaders and firmware-update infrastructure for industrial and IoT deployments, with exposure concentrated in its Barebox bootloader and RAUC update framework. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through memory-safety and cryptographic-verification weakness classes including out-of-bounds reads and writes, as well as improper signature validation that are characteristic of low-level firmware components. Defenders managing devices using this vendor's bootloader or update stack should treat disclosed flaws as high-priority given their position in the boot and provisioning chain; current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pengutronix over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 5, 2019
6 years ago
Most Recent CVE
May 16, 2026
69 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-46728HIGH
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
May 16, 20268.837NONO
CVE-2026-34963HIGH
barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation
May 11, 20268.435NONO
CVE-2019-15938CRITICAL
Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_req in fs/nfs.c because a length field is directly used for a memcpy.
Sep 5, 20199.832NONO
CVE-2019-15937CRITICAL
Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_reply in net/nfs.c because a length field is directly used for a memcpy.
Sep 5, 20199.832NONO
CVE-2026-34961HIGH
barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing validation of the eh_entries field against buffer capacity in f
May 11, 20267.730NONO
CVE-2020-13910CRITICAL
Pengutronix Barebox through v2020.05.0 has an out-of-bounds read in nfs_read_reply in net/nfs.c because a field of an incoming network packet is directly used as a length field wit
Jun 7, 20209.129NONO
CVE-2026-34962MEDIUM
barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_common.c where the ext4fs_iterate_dir() function fails to va
May 11, 20266.228NONO
CVE-2026-33243HIGH
barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature veri
Mar 20, 20268.228NONO
CVE-2026-34960MEDIUM
barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that fails to verify the options poin
May 11, 20266.527NONO
CVE-2021-37848HIGH
common/password.c in Pengutronix barebox through 2021.07.0 leaks timing information because strncmp is used during hash comparison.
Aug 2, 20217.524NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
27%
53%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (33.3%)
Network7 (46.7%)
Unknown0 (0.0%)
Physical2 (13.3%)
Adjacent Network1 (6.7%)
Attack Complexity
Low12 (80.0%)
High3 (20.0%)
Unknown0 (0.0%)
User Interaction
None15 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (6.7%)
High2 (13.3%)
None12 (80.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pengutronix.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pengutronix — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pengutronix's Products

View all 4 CNAs →

Top CWEs