RIOT OS is a lightweight, open-source operating system designed for resource-constrained embedded and Internet-of-Things devices, where its narrow but strategically important product focus places it among the more prominent vendors in the embedded systems landscape. Despite the vendor's concentrated portfolio, the breadth of device types and deployment contexts that rely on RIOT across industrial, automotive, and connected-device sectors creates a widely distributed attack surface that spans heterogeneous hardware and use cases. The vulnerability disclosures affecting RIOT reflect the complexity inherent to a real-time kernel and networking stack serving diverse embedded platforms, though the specific weakness classes and their patterns have not yet stabilized into a consistent, recurring profile. Defenders deploying RIOT-based devices should monitor vendor advisories and assess the sensitivity of each device class to firmware updates; current severity, exploitation status, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Riot Os over time
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66647CRITICAL RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. A vulnerability was disc | Dec 17, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-22214CRITICAL RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos utility due to missing bounds checking when processing incom | Jan 12, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-22213CRITICAL RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapslip6 utility. The vulnerability is caused by unsafe string con | Jan 12, 2026 | 9.8 | 33 | NO | NO |
CVE-2021-27427CRITICAL RIOT OS version 2020.01.1 is vulnerable to integer wrap-around in its implementation of calloc function, which can lead to arbitrary memory allocation, resulting in unexpected beha | May 3, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-15350CRITICAL RIOT 2020.04 has a buffer overflow in the base64 decoder. The decoding function base64_decode() uses an output buffer estimation function to compute the required buffer capacity an | Jul 7, 2020 | 9.8 | 31 | NO | NO |
CVE-2023-33975CRITICAL RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. In version 2023.01 and prior, an attacker ca | May 30, 2023 | 9.8 | 30 | NO | NO |
CVE-2026-27703CRITICAL RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. In 2026.01 and earlier, | Mar 11, 2026 | 9.8 | 29 | NO | NO |
CVE-2023-24823CRITICAL RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker ca | Apr 24, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-24819CRITICAL RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker ca | Apr 24, 2023 | 9.8 | 29 | NO | NO |
CVE-2021-27698CRITICAL RIOT-OS 2021.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c through the _parse_options() function. | Apr 6, 2021 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Riot Os.
Media articles that mention a CVE ID that affects a product developed by Riot Os — matched by CVE ID, not by vendor name.