VendorsRIOT-OSriotall versions
Vulnerabilities

RIOT-OS RIOT

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

40CVEs
CVE-2021-27427
RIOT OS Integer Overflow or Wraparound
Published 2022-05-03 · Modified
9.8EPSS 0.017
CVE-2019-1000006
RIOT RIOT-OS version after commit 7af03ab624db0412c727eed9ab7630a5282e2fd3 contains a Buffer Overflow vulnerability in sock_dns, an implementation of the DNS protocol utilizing the RIOT sock API that can result in Remote code executing. This attack appears to be exploitable via network connectivity.
Published 2019-02-04 · Modified
9.8EPSS 0.016
CVE-2024-32017
Buffer overflows in RIOT
Published 2024-05-01 · Analyzed
9.8EPSS 0.015
CVE-2023-33975
RIOT-OS vulnerable to Out of Bounds Write in _rbuf_add
Published 2023-05-30 · Modified
9.8EPSS 0.015
CVE-2020-15350
RIOT 2020.04 has a buffer overflow in the base64 decoder. The decoding function base64_decode() uses an output buffer estimation function to compute the required buffer capacity and validate against the provided buffer size. The base64_estimate_decode_size() function calculates the expected decoded size with an arithmetic round-off error and does not take into account possible padding bytes. Due to this underestimation, it may be possible to craft base64 input that causes a buffer overflow.
Published 2020-07-07 · Modified
9.8EPSS 0.015
CVE-2021-27697
RIOT-OS 2021.01 contains a buffer overflow vulnerability in sys/net/gnrc/routing/rpl/gnrc_rpl_validation.c through the gnrc_rpl_validation_options() function.
Published 2021-04-06 · Modified
9.8EPSS 0.013
CVE-2021-27698
RIOT-OS 2021.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c through the _parse_options() function.
Published 2021-04-06 · Modified
9.8EPSS 0.012
CVE-2021-27357
RIOT-OS 2020.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c.
Published 2021-04-06 · Modified
9.8EPSS 0.012
CVE-2023-24823
RIOT-OS vulnerable to Packet Type Confusion during IPHC send
Published 2023-04-24 · Modified
9.8EPSS 0.010
CVE-2023-24819
RIOT-OS vulnerable to Buffer Overflow during IPHC receive
Published 2023-04-24 · Modified
9.8EPSS 0.010
CVE-2025-66647
RIOT OS has buffer overflow in gnrc_ipv6_ext_frag_reass
Published 2025-12-17 · Analyzed
9.8EPSS 0.010
CVE-2025-53888
RIOT-OS has an ineffective size check that can lead to buffer overflow in link layer address filter /sys/net/link_layer/l2filter/l2filter.c
Published 2025-07-18 · Analyzed
9.8EPSS 0.007
CVE-2026-27703
RIOT has an Out-of-Bounds Write in nanoCoAP Handler
Published 2026-03-11 · Analyzed
9.8EPSS 0.005
CVE-2026-22214
RIOT OS <= 2026.01-devel-317 Stack-Based Buffer Overflow in ethos Serial Frame Parser
Published 2026-01-12 · Analyzed
9.8EPSS 0.005
CVE-2026-22213
RIOT OS <= 2026.01-devel-317 Stack-Based Buffer Overflow in tapslip6 Utility
Published 2026-01-12 · Analyzed
9.8EPSS 0.004
CVE-2026-25139
RIOT Vulnerable to Multiple Out-of-Bounds Read When Processing Received 6LoWPAN SFR Fragments
Published 2026-02-04 · Analyzed
9.1EPSS 0.005
CVE-2024-32018
Ineffective size check due to assert() and buffer overflow in RIOT
Published 2024-05-01 · Analyzed
9.0EPSS 0.015
CVE-2024-31225
Lack of size check and buffer overflow in RIOT
Published 2024-05-01 · Analyzed
9.0EPSS 0.013
CVE-2019-15134
RIOT through 2019.07 contains a memory leak in the TCP implementation (gnrc_tcp), allowing an attacker to consume all memory available for network packets and thus effectively stopping all network threads from working. This is related to _receive in sys/net/gnrc/transport_layer/tcp/gnrc_tcp_eventloop.c upon receiving an ACK before a SYN.
Published 2019-08-17 · Modified
7.8EPSS 0.015
CVE-2019-17389
In RIOT 2019.07, the MQTT-SN implementation (asymcute) mishandles errors occurring during a read operation on a UDP socket. The receive loop ends. This allows an attacker (via a large packet) to prevent a RIOT MQTT-SN client from working until the device is restarted.
Published 2019-10-09 · Modified
7.8EPSS 0.014
CVE-2021-31663
RIOT-OS 2021.01 before commit bc59d60be60dfc0a05def57d74985371e4f22d79 contains a buffer overflow which could allow attackers to obtain sensitive information.
Published 2021-06-18 · Modified
7.5EPSS 0.016
CVE-2019-16754
RIOT 2019.07 contains a NULL pointer dereference in the MQTT-SN implementation (asymcute), potentially allowing an attacker to crash a network node running RIOT. This requires spoofing an MQTT server response. To do so, the attacker needs to know the MQTT MsgID of a pending MQTT protocol message and the ephemeral port used by RIOT's MQTT implementation. Additionally, the server IP address is required for spoofing the packet.
Published 2019-09-24 · Modified
7.5EPSS 0.015
CVE-2019-15702
In the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all inputs, allowing a denial-of-service, because sys/net/gnrc/transport_layer/tcp/gnrc_tcp_option.c has an infinite loop for an unknown zero-length option.
Published 2019-08-27 · Modified
7.5EPSS 0.014
CVE-2021-31661
RIOT-OS 2021.01 before commit 609c9ada34da5546cffb632a98b7ba157c112658 contains a buffer overflow that could allow attackers to obtain sensitive information.
Published 2021-06-18 · Modified
7.5EPSS 0.013
CVE-2021-31660
RIOT-OS 2021.01 before commit 85da504d2dc30188b89f44c3276fc5a25b31251f contains a buffer overflow which could allow attackers to obtain sensitive information.
Published 2021-06-18 · Modified
7.5EPSS 0.013
CVE-2021-31662
RIOT-OS 2021.01 before commit 07f1254d8537497552e7dce80364aaead9266bbe contains a buffer overflow which could allow attackers to obtain sensitive information.
Published 2021-06-18 · Modified
7.5EPSS 0.013
CVE-2021-31664
RIOT-OS 2021.01 before commit 44741ff99f7a71df45420635b238b9c22093647a contains a buffer overflow which could allow attackers to obtain sensitive information.
Published 2021-06-18 · Modified
7.5EPSS 0.013
CVE-2023-24818
RIOT-OS vulnerable to null pointer dereference during fragment forwarding
Published 2023-04-24 · Modified
7.5EPSS 0.012
CVE-2023-33973
RIOT-OS vulnerable to NULL pointer dereference during NHC encoding
Published 2023-05-30 · Modified
7.5EPSS 0.010
CVE-2023-24825
RIOT-OS vulnerable to NULL pointer dereference in gnrc_pktbuf_mark
Published 2023-05-30 · Modified
7.5EPSS 0.010
CVE-2023-24821
RIOT-OS vulnerable to Integer Underflow during defragmentation
Published 2023-04-24 · Modified
7.5EPSS 0.009
CVE-2023-24822
RIOT-OS vulnerable to Null Pointer dereference during IPHC encoding
Published 2023-04-24 · Modified
7.5EPSS 0.009
CVE-2023-24820
RIOT-OS vulnerable to Integer Underflow during IPHC receive
Published 2023-04-24 · Modified
7.5EPSS 0.009
CVE-2023-24826
Usage of Uninitialized Timer during forwarding of Fragments with SFR
Published 2023-05-30 · Modified
7.5EPSS 0.008
CVE-2024-52802
RIOT-OS missing dhcpv6_opt_t minimum header length check
Published 2024-11-22 · Analyzed
7.5EPSS 0.008
CVE-2024-53980
Spoofed length byte traps CC2538 in endless loop
Published 2024-11-29 · Analyzed
7.5EPSS 0.008
CVE-2023-33974
RIOT-OS vulnerable to Race Condition in SFR Timeout
Published 2023-05-30 · Modified
7.5EPSS 0.007
CVE-2025-66646
RIOT-OS has NULL pointer dereference in gnrc_ipv6_ext_frag_reass
Published 2025-12-17 · Analyzed
7.5EPSS 0.007
CVE-2023-24817
RIOT-OS vulnerable to Out of Bounds write in routing with SRH
Published 2023-05-30 · Modified
7.5EPSS 0.006
CVE-2021-41061
In RIOT-OS 2021.01, nonce reuse in 802.15.4 encryption in the ieee820154_security component allows attackers to break encryption by triggering reboots.
Published 2021-09-15 · Modified
5.5EPSS 0.002