Virtualsquare maintains a specialized embedded networking library, PicoTCP, designed for resource-constrained and embedded systems where standard TCP/IP stacks are impractical. The library's disclosed vulnerabilities center on exception-handling and arithmetic-logic gaps typical of low-level network implementations, including improper condition checks, calculation errors, and uninitialized resource use.
The number and severity of CVEs published that impact products developed by Virtualsquare over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-35849HIGH VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not properly check whether header sizes would result in accessing data outside of a packet. | Jun 19, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-35847HIGH VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not have an MSS lower bound (e.g., it could be zero). | Jun 19, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-35846HIGH VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not check the transport layer length in a frame before performing port filtering. | Jun 19, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-35848HIGH VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 lacks certain size calculations before attempting to set a value of an mss structure member. | Jun 19, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Virtualsquare.
Media articles that mention a CVE ID that affects a product developed by Virtualsquare — matched by CVE ID, not by vendor name.