Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Treck

First CVE: Jun 2, 2020Active for: 6 yearsTotal CVEs: 24
54.8
VTI Score
TOP TARGET

Treck develops a narrowly scoped embedded TCP/IP stack used across industrial, medical, and IoT devices where memory footprint and simplicity are paramount. Despite a minimal product portfolio, the vendor's stack reaches a prominent position in the vulnerability landscape due to its deep integration into long-lived networked appliances that are difficult to patch. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through memory-safety and bounds-checking weakness classes including out-of-bounds reads and writes, integer underflow, and improper input validation—flaws endemic to low-level network-protocol handling in constrained environments. The combination of embedded deployment, limited upgrade paths in fielded devices, and memory-safety exposure makes this vendor a persistent target for device compromise and lateral movement. Current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
12.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
4.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Treck over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 2, 2020
6 years ago
Most Recent CVE
Dec 22, 2020
2,042 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-11899MEDIUM
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
Jun 17, 20205.461YESNO
CVE-2020-11896CRITICAL
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.
Jun 17, 202010.052NONO
CVE-2020-11901CRITICAL
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.
Jun 17, 20209.041NONO
CVE-2020-25066CRITICAL
A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or to possibly execute arbitrary
Dec 22, 20209.832NONO
CVE-2020-11900HIGH
The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free.
Jun 17, 20208.232NONO
CVE-2020-11898CRITICAL
The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers to trigger an information leak.
Jun 17, 20209.132NONO
CVE-2020-10136MEDIUM
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and o
Jun 2, 20205.330NONO
CVE-2020-11902HIGH
The Treck TCP/IP stack before 6.0.1.66 has an IPv6OverIPv4 tunneling Out-of-bounds Read.
Jun 17, 20207.328NONO
CVE-2020-11897CRITICAL
The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets.
Jun 17, 202010.028NONO
CVE-2020-27337HIGH
An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the IPv6 component allows an unauthenticated remote attacker to cause an Out of Bounds Write, an
Dec 22, 20207.324NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
58%
21%
21%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network8 (33.3%)
Attack Complexity
Low23 (95.8%)
High1 (4.2%)
Unknown0 (0.0%)
User Interaction
None24 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None24 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
1 CVE
4.2% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Treck.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Treck — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Treck's Products

View all 2 CNAs →

Top CWEs