logo

Critical 9.4 CVSS Zephyr RTOS Flaw Exposes Millions of IoT Devices to RCE

ID: 7c492016-825a-5bfb-8f8c-662da095b647

STIX ID: report--7c492016-825a-5bfb-8f8c-662da095b647

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-09

Date Updated: 2026-04-23

Author: Ddos

...
...

**Critical Zephyr DNS parsing vulnerability (CVE-2026-1678):** A memory-safety flaw in dns_unpack_name() can be triggered by a crafted DNS response to cause an out-of-bounds write and potentially remote code execution on devices running Zephyr with the DNS resolver enabled; default production builds (CONFIG_ASSERT disabled) are particularly at risk. Apply vendor patches, consider enabling CONFIG_ASSERT for sensitive devices, and review DNS buffer configuration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.