{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/contiki-ng/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-5855"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Contiki-NG"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Contiki-NG"],"content_html":"\u003cp\u003eCVE-2026-5855 describes a critical out-of-bounds read vulnerability within the Contiki-NG LwM2M implementation, specifically affecting the \u003ccode\u003elwm2m_tlv_read()\u003c/code\u003e function located in \u003ccode\u003eos/services/lwm2m/lwm2m-tlv.c\u003c/code\u003e. The parser fails to respect the caller-supplied buffer length argument and performs reads up to six bytes beyond the intended heap buffer bounds without appropriate validation.\u003c/p\u003e\n\u003cp\u003eWhen operating in LwM2M NoSec mode, which is the default configuration for many constrained devices, this vulnerability can be triggered by an unauthenticated attacker sending a crafted CoAP WRITE request. The vulnerability is triggered when the final TLV field in the request contains exactly one byte. Successful exploitation allows for the disclosure of sensitive heap memory, potentially exposing cryptographic key material, peer addresses, and other internal state information. Furthermore, the resulting corruption of the \u003ccode\u003etlv_len\u003c/code\u003e field can lead to downstream processing logic failures or further memory corruption.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-5855 enables unauthorized information disclosure from the device's heap memory. Given the context of constrained IoT devices running Contiki-NG, this may result in the compromise of static cryptographic keys or network topology metadata. The vulnerability is particularly dangerous because it does not require authentication in default NoSec deployments, increasing the likelihood of remote exploitation against exposed IoT infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit network edge traffic for CoAP WRITE requests targeting constrained devices running Contiki-NG.\u003c/li\u003e\n\u003cli\u003eImplement strict ingress filtering to restrict CoAP traffic to authorized network segments, as NoSec LwM2M is inherently vulnerable to unauthenticated access.\u003c/li\u003e\n\u003cli\u003eApply the vendor-provided patch for \u003ccode\u003eos/services/lwm2m/lwm2m-tlv.c\u003c/code\u003e to enforce correct buffer bounds checking in the \u003ccode\u003elwm2m_tlv_read\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eMonitor for unusual CoAP traffic patterns, specifically malformed WRITE payloads characterized by single-byte final TLVs that may indicate exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T23:31:04Z","date_published":"2026-08-06T23:30:49Z","id":"https://feed.craftedsignal.io/briefs/2026-08-contiki-ng-oob-read/","summary":"Contiki-NG's LwM2M TLV parser contains an out-of-bounds read vulnerability that allows unauthenticated attackers to disclose heap memory contents via crafted CoAP WRITE requests.","title":"CVE-2026-5855: Out-of-Bounds Read Vulnerability in Contiki-NG LwM2M Parser","url":"https://feed.craftedsignal.io/briefs/2026-08-contiki-ng-oob-read/"}],"language":"en","title":"CraftedSignal Threat Feed - Contiki-NG","version":"https://jsonfeed.org/version/1.1"}