CVE-2024-36671: Nodemcu

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

nodemcu before v3.0.0-release_20240225 was discovered to contain an integer overflow via the getnum function at /modules/struct.c.

Affected products

  • Nodemcu Nodemcu: before 3.0.0-release_20240225 (fixed in 3.0.0-release_20240225)

Published 2024-11-29. Last modified 2026-06-17.