Junglewise Threat Intelligence

CVE-2026-22212: TinyOS stack overflow in mcp2200gpio utility

CVE-2026-22212 · Severity: info · CVSS 4.8 · Published 2026-01-12

Executive brief

TinyOS is an operating system designed for low-power wireless devices like sensors and smart meters. A security flaw in its mcp2200gpio utility allows a local user to crash the application or potentially take control of the system by creating files with unusually long names. This could lead to service disruptions or unauthorized access on affected embedded devices.

Technical details

A stack-based buffer overflow exists in the mcp2200gpio utility of TinyOS due to the unsafe use of strcpy() and strcat() functions. When the utility performs automatic device discovery by scanning /dev/usb/, it concatenates filenames into a fixed-size 255-byte stack buffer (temppath) without bounds checking. A local attacker with the ability to create files in /dev/usb/ can provide a specially crafted filename that exceeds this buffer. This results in stack memory corruption, leading to a denial of service (application crash) or potentially arbitrary code execution in non-hardened environments. The vulnerability is tracked as CWE-121.

Affected products

  • TinyOS TinyOS up to and including 2.1.2

Timeline

  • 2026-01-08: disclosed: Initial disclosure on Full Disclosure mailing list
  • 2026-01-12: advisory: NVD and VulnCheck advisory published

References

Related threats