Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Riot Os

First CVE: Feb 4, 2019Active for: 7 yearsTotal CVEs: 79

RIOT OS is a lightweight, open-source operating system designed for resource-constrained embedded and Internet-of-Things devices, where its narrow but strategically important product focus places it among the more prominent vendors in the embedded systems landscape. Despite the vendor's concentrated portfolio, the breadth of device types and deployment contexts that rely on RIOT across industrial, automotive, and connected-device sectors creates a widely distributed attack surface that spans heterogeneous hardware and use cases. The vulnerability disclosures affecting RIOT reflect the complexity inherent to a real-time kernel and networking stack serving diverse embedded platforms, though the specific weakness classes and their patterns have not yet stabilized into a consistent, recurring profile. Defenders deploying RIOT-based devices should monitor vendor advisories and assess the sensitivity of each device class to firmware updates; current severity, exploitation status, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
40
Total CVEs
More Total CVEs than 98% of tracked vendors
5.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Riot Os over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 4, 2019
7 years ago
Most Recent CVE
Mar 11, 2026
136 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-66647CRITICAL
RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. A vulnerability was disc
Dec 17, 20259.834NONO
CVE-2026-22214CRITICAL
RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos utility due to missing bounds checking when processing incom
Jan 12, 20269.833NONO
CVE-2026-22213CRITICAL
RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapslip6 utility. The vulnerability is caused by unsafe string con
Jan 12, 20269.833NONO
CVE-2021-27427CRITICAL
RIOT OS version 2020.01.1 is vulnerable to integer wrap-around in its implementation of calloc function, which can lead to arbitrary memory allocation, resulting in unexpected beha
May 3, 20229.831NONO
CVE-2020-15350CRITICAL
RIOT 2020.04 has a buffer overflow in the base64 decoder. The decoding function base64_decode() uses an output buffer estimation function to compute the required buffer capacity an
Jul 7, 20209.831NONO
CVE-2023-33975CRITICAL
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. In version 2023.01 and prior, an attacker ca
May 30, 20239.830NONO
CVE-2026-27703CRITICAL
RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. In 2026.01 and earlier,
Mar 11, 20269.829NONO
CVE-2023-24823CRITICAL
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker ca
Apr 24, 20239.829NONO
CVE-2023-24819CRITICAL
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker ca
Apr 24, 20239.829NONO
CVE-2021-27698CRITICAL
RIOT-OS 2021.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c through the _parse_options() function.
Apr 6, 20219.829NONO
View all 40 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products40 CVEs
50%
45%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.5%)
Network39 (97.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (90.0%)
High4 (10.0%)
Unknown0 (0.0%)
User Interaction
None40 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (2.5%)
High0 (0.0%)
None39 (97.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (40 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Riot Os.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Riot Os — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Riot Os's Products

View all 4 CNAs →

Top CWEs