Impact
A fault in the RIOT nanocoap_fileserver causes it to ignore errors returned by response initialization when a CoAP request contains an oversized extended token. The bug leads to a stale response buffer and triggers an assertion during size calculation, terminating the service or device task. This flaw is a high‑severity remote denial of service that can be exercised over the network.
Affected Systems
The vulnerability affects RIOT‑OS releases from 2023.07 through 2026.07. It is present in all embedded devices that run these RIOT versions and have the nanocoap_fileserver component enabled, especially those configured to accept extended tokens.
Risk and Exploitability
The CVSS score of 7.5 indicates high impact, while no EPSS data is currently available and the flaw is not listed in the CISA KEV catalog. An attacker can trigger it via a crafted CoAP request sent from the network, causing the target to crash. With no patch yet released, the risk remains high until official remediation arrives.
OpenCVE Enrichment