CVE-2020-12140: Contiki-NG

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

A buffer overflow in os/net/mac/ble/ble-l2cap.c in the BLE stack in Contiki-NG 4.4 and earlier allows an attacker to execute arbitrary code via malicious L2CAP frames.

Affected products

Published 2021-12-07. Last modified 2026-06-17.