Critical 9.4 CVSS Zephyr RTOS Flaw Exposes Millions of IoT Devices to RCE
ID: 7c492016-825a-5bfb-8f8c-662da095b647
STIX ID: report--7c492016-825a-5bfb-8f8c-662da095b647
Feed Name: securityonline.info
Threat Score
**Critical Zephyr DNS parsing vulnerability (CVE-2026-1678):** A memory-safety flaw in dns_unpack_name() can be triggered by a crafted DNS response to cause an out-of-bounds write and potentially remote code execution on devices running Zephyr with the DNS resolver enabled; default production builds (CONFIG_ASSERT disabled) are particularly at risk. Apply vendor patches, consider enabling CONFIG_ASSERT for sensitive devices, and review DNS buffer configuration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
