Executive brief
Contiki-NG is an operating system for IoT embedded devices. Its MQTT client contains a buffer overflow vulnerability where malformed MQTT messages with oversized topic names can corrupt adjacent memory structures and enable remote code execution on IoT devices. An attacker with network access to the MQTT broker can exploit this to take control of connected devices or extract sensitive data.
Technical details
The vulnerability exists in parse_publish_vhdr() within os/net/app-layer/mqtt/mqtt.c. The parser prematurely sets a topic_len_received flag before validating the topic length against a 64-byte limit, causing the validation guard to be skipped on subsequent TCP segments. When a new segment arrives, the parser re-invokes with the persisted flag set, skipping the length-reading block and falling through to an unguarded memcpy() that uses an unvalidated 16-bit topic_len value as the copy size. This overwrites the 65-byte topic[] buffer into adjacent struct fields including payload_chunk pointers. Contiki-NG's MQTT implementation does not support TLS, leaving connections plaintext and vulnerable to man-in-the-middle exploitation by a compromised or attacker-controlled broker. The arbitrary-pointer-write primitive can lead to information disclosure, denial of service, or remote code execution on memory-unprotected embedded targets.
Affected products
- Contiki-NG Contiki-NG prior to commit a34a2dbdc8bea784bd2ae5079aa4be520cd74f2d (2026-07-10)
Timeline
- 2026-08-06: disclosed: Advisory published
- 2026-07-10: patched: Fix merged in PR #3163 (mqtt: harden TCP input parsing against malformed and coalesced packets)