CVE-2021-41061
5.5 MEDIUMIn RIOT-OS 2021.01, nonce reuse in 802.15.4 encryption in the ieee820154_security component allows attackers to break encryption by trigg...
Published: 2021-09-15 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 5.5 MEDIUM
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- CWE
- CWE-330
Affected products
| Vendor | Product |
|---|---|
| riot-os | riot |
Description
In RIOT-OS 2021.01, nonce reuse in 802.15.4 encryption in the ieee820154_security component allows attackers to break encryption by triggering reboots.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2021-41061
- [Exploit reference]https://github.com/RIOT-OS/RIOT/issues/16844
- [Exploit reference]https://github.com/RIOT-OS/RIOT/issues/16844
Related CVEs
Same CWE
- CVE-2026-50009 — Netty is a network application framework for development of protocol servers and clients (4.8 MEDIUM)
- CVE-2026-45673 — Netty is a network application framework for development of protocol servers and clients (6.8 MEDIUM)
- CVE-2026-41701 — Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter (4.4 MEDIUM)
- CVE-2026-41838 — IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in co... (4.8 MEDIUM)
- CVE-2026-41207 — The netty incubator codec.bhttp is a java language binary http parser (5.3 MEDIUM)