Ti's vulnerability footprint centers on a family of embedded wireless and microcontroller software development kits, including SimpleLink and CC3x00 platforms, that serve the Internet of Things and embedded systems market. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; the exposure recurs through memory-safety and cryptographic weakness classes including integer overflow, buffer overflows, out-of-bounds writes, and improper cryptographic signature verification that are characteristic of low-level embedded firmware and protocol stacks. These SDKs often ship in long-lived connected devices with limited update mechanisms, making the embedded nature of the flaws particularly consequential for defenders managing IoT deployments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ti over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-29468CRITICAL The Texas Instruments (TI) WiLink WL18xx MCP driver does not limit the number of information elements (IEs) of type XCC_EXT_1_IE_ID or XCC_EXT_2_IE_ID that can be parsed in a manag | Aug 14, 2023 | 9.8 | 34 | NO | NO |
CVE-2021-22671CRITICAL Multiple integer overflow issues exist while processing long domain names, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 a | May 7, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-22679CRITICAL The affected product is vulnerable to an integer overflow while processing HTTP headers, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: | May 7, 2021 | 9.8 | 30 | NO | NO |
CVE-2018-16986HIGH Texas Instruments BLE-STACK v2.2.1 for SimpleLink CC2640 and CC2650 devices allows remote attackers to execute arbitrary code via a malformed packet that triggers a buffer overflow | Nov 6, 2018 | 8.8 | 29 | NO | NO |
CVE-2019-15948HIGH Texas Instruments CC256x and WL18xx dual-mode Bluetooth controller devices, when LE scan mode is used, allow remote attackers to trigger a buffer overflow via a malformed Bluetooth | Nov 13, 2019 | 8.8 | 27 | NO | NO |
CVE-2021-22677HIGH An integer overflow exists in the APIs of the host MCU while trying to connect to a WIFI network may lead to issues such as a denial-of-service condition or code execution on the S | May 7, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-22673HIGH The affected product is vulnerable to stack-based buffer overflow while processing over-the-air firmware updates from the CDN server, which may allow an attacker to remotely execut | May 7, 2021 | 8.0 | 25 | NO | NO |
CVE-2020-27890HIGH The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Write Attributes No Response message. It crashes in zclPar | Oct 27, 2020 | 8.2 | 25 | NO | NO |
CVE-2022-25334HIGH The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) lacks a bounds check on the signature size field in the SK_LOAD module loading routine, presen | Oct 19, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-25333HIGH The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) performs an RSA check implemented in mask ROM when loading a module through the SK_LOAD routin | Oct 19, 2023 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ti.
Media articles that mention a CVE ID that affects a product developed by Ti — matched by CVE ID, not by vendor name.