Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ti

First CVE: Aug 7, 2018Active for: 8 yearsTotal CVEs: 28
26.7
VTI Score
Low

Ti's vulnerability footprint centers on a family of embedded wireless and microcontroller software development kits, including SimpleLink and CC3x00 platforms, that serve the Internet of Things and embedded systems market. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; the exposure recurs through memory-safety and cryptographic weakness classes including integer overflow, buffer overflows, out-of-bounds writes, and improper cryptographic signature verification that are characteristic of low-level embedded firmware and protocol stacks. These SDKs often ship in long-lived connected devices with limited update mechanisms, making the embedded nature of the flaws particularly consequential for defenders managing IoT deployments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ti over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 7, 2018
7 years ago
Most Recent CVE
Sep 12, 2024
680 days ago

Products(59 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-29468CRITICAL
The Texas Instruments (TI) WiLink WL18xx MCP driver does not limit the number of information elements (IEs) of type XCC_EXT_1_IE_ID or XCC_EXT_2_IE_ID that can be parsed in a manag
Aug 14, 20239.834NONO
CVE-2021-22671CRITICAL
Multiple integer overflow issues exist while processing long domain names, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 a
May 7, 20219.831NONO
CVE-2021-22679CRITICAL
The affected product is vulnerable to an integer overflow while processing HTTP headers, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK:
May 7, 20219.830NONO
CVE-2018-16986HIGH
Texas Instruments BLE-STACK v2.2.1 for SimpleLink CC2640 and CC2650 devices allows remote attackers to execute arbitrary code via a malformed packet that triggers a buffer overflow
Nov 6, 20188.829NONO
CVE-2019-15948HIGH
Texas Instruments CC256x and WL18xx dual-mode Bluetooth controller devices, when LE scan mode is used, allow remote attackers to trigger a buffer overflow via a malformed Bluetooth
Nov 13, 20198.827NONO
CVE-2021-22677HIGH
An integer overflow exists in the APIs of the host MCU while trying to connect to a WIFI network may lead to issues such as a denial-of-service condition or code execution on the S
May 7, 20217.825NONO
CVE-2021-22673HIGH
The affected product is vulnerable to stack-based buffer overflow while processing over-the-air firmware updates from the CDN server, which may allow an attacker to remotely execut
May 7, 20218.025NONO
CVE-2020-27890HIGH
The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Write Attributes No Response message. It crashes in zclPar
Oct 27, 20208.225NONO
CVE-2022-25334HIGH
The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) lacks a bounds check on the signature size field in the SK_LOAD module loading routine, presen
Oct 19, 20238.824NONO
CVE-2022-25333HIGH
The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) performs an RSA check implemented in mask ROM when loading a module through the SK_LOAD routin
Oct 19, 20238.824NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
36%
54%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local9 (32.1%)
Network10 (35.7%)
Unknown0 (0.0%)
Physical1 (3.6%)
Adjacent Network8 (28.6%)
Attack Complexity
Low25 (89.3%)
High3 (10.7%)
Unknown0 (0.0%)
User Interaction
None27 (96.4%)
Unknown0 (0.0%)
Required1 (3.6%)
Privileges Required
Low9 (32.1%)
High2 (7.1%)
None17 (60.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ti.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ti — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ti's Products

View all 5 CNAs →

Top CWEs