Treck develops a narrowly scoped embedded TCP/IP stack used across industrial, medical, and IoT devices where memory footprint and simplicity are paramount. Despite a minimal product portfolio, the vendor's stack reaches a prominent position in the vulnerability landscape due to its deep integration into long-lived networked appliances that are difficult to patch. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through memory-safety and bounds-checking weakness classes including out-of-bounds reads and writes, integer underflow, and improper input validation—flaws endemic to low-level network-protocol handling in constrained environments. The combination of embedded deployment, limited upgrade paths in fielded devices, and memory-safety exposure makes this vendor a persistent target for device compromise and lateral movement. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Treck over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11899MEDIUM The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. | Jun 17, 2020 | 5.4 | 61 | YES | NO |
CVE-2020-11896CRITICAL The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling. | Jun 17, 2020 | 10.0 | 52 | NO | NO |
CVE-2020-11901CRITICAL The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response. | Jun 17, 2020 | 9.0 | 41 | NO | NO |
CVE-2020-25066CRITICAL A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or to possibly execute arbitrary | Dec 22, 2020 | 9.8 | 32 | NO | NO |
CVE-2020-11900HIGH The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free. | Jun 17, 2020 | 8.2 | 32 | NO | NO |
CVE-2020-11898CRITICAL The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers to trigger an information leak. | Jun 17, 2020 | 9.1 | 32 | NO | NO |
CVE-2020-10136MEDIUM IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and o | Jun 2, 2020 | 5.3 | 30 | NO | NO |
CVE-2020-11902HIGH The Treck TCP/IP stack before 6.0.1.66 has an IPv6OverIPv4 tunneling Out-of-bounds Read. | Jun 17, 2020 | 7.3 | 28 | NO | NO |
CVE-2020-11897CRITICAL The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets. | Jun 17, 2020 | 10.0 | 28 | NO | NO |
CVE-2020-27337HIGH An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the IPv6 component allows an unauthenticated remote attacker to cause an Out of Bounds Write, an | Dec 22, 2020 | 7.3 | 24 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Treck.
Media articles that mention a CVE ID that affects a product developed by Treck — matched by CVE ID, not by vendor name.