Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ripple20 is the name given to 19 vulnerabilities reported in Treck TCP/IP stack software used in embedded products. Some could allow remote code execution, information disclosure, or denial of service, but a device is not automatically vulnerable just because it uses Treck. To assess a particular product, match its exact model and firmware or software version to the device maker’s security advisory.

What is Ripple20?

Ripple20 refers to a group of vulnerabilities researched and reported by JSOF in Treck TCP/IP stack implementations. A TCP/IP stack provides software components that let a device communicate over IP networks. Treck code can be incorporated into embedded products in different ways, including as source code, modified or reused code, or static and dynamic libraries. CERT/CC also says that some of the vulnerabilities affect historically related KASAGO TCP/IP middleware.

The Cyber Security Agency of Singapore reported 19 vulnerabilities in June 2020, four of them rated critical. The group is not a single flaw with one uniform impact: the affected component, product implementation, configuration, and enabled network features all matter.

What can a Ripple20 vulnerability let an attacker do?

Depending on the specific vulnerability and how a product uses the affected code, consequences can include denial of service, information disclosure, or arbitrary code execution. CERT/CC says a remote, unauthenticated attacker may be able to use specially crafted network packets to cause these outcomes. That describes potential impact, not proof that every Treck-using device is reachable or exploitable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
VIMTAG 2.5K Cameras for Home Security Outdoor/Indoor, Color Night Vision Security Camera for Baby/Pet/Dog/Nanny, Light/Siren, Motion Detection, 2-Way Audio, Work with Alexa, Cloud/Card Storage, 2Pcs
  • 𝐄𝐚𝐬𝐲 𝐒𝐞𝐭𝐮𝐩 𝐈𝐧𝐝𝐨𝐨𝐫/𝐎𝐮𝐭𝐝𝐨𝐨𝐫 𝐂𝐚𝐦𝐞𝐫𝐚 — 2.5K HD video, vibrant color night vision and IP66, ensuring you never miss a moment, day or night,rainy or sunny. With dual-band 2.4G/5G WiFi & Plug and play setup of the cameras for home security - just download app and scan QR code! No tools needed for tabletop use, mounting screws included for walls
  • 𝟐.𝟓𝐊 𝐐𝐇𝐃 & 𝐂𝐨𝐥𝐨𝐫 𝐍𝐢𝐠𝐡𝐭 𝐕𝐢𝐬𝐢𝐨𝐧 — Experience crystal-clear visibility day and night with full-color night vision enhanced by a built-in white light. Perfect as a baby monitor, pet camera, or security camera to monitor your home inside and out
  • 𝐒𝐦𝐚𝐫𝐭 𝐀𝐈 𝐃𝐞𝐭𝐞𝐜𝐭𝐢𝐨𝐧 & 𝐀𝐥𝐞𝐫𝐭𝐬 — Stay informed about what matters most with human/motion/sound detection up to 33 feet away. The camera deters intruders with flashing lights and a siren while sending instant alerts to your phone — keeping you one step ahead of any suspicious activity. Call +1 (978) 437-5767 for expert support with setting up and optimizing Vimtag cameras, available Monday to Friday, 9:00 AM - 6:00 PM (ET)
  • 𝐄𝐧𝐡𝐚𝐧𝐜𝐞𝐝 𝐓𝐰𝐨-𝐖𝐚𝐲 𝐀𝐮𝐝𝐢𝐨 - Communicate effortlessly with guests or check in on pets using the upgraded two-way audio feature of this indoor camera, allowing you to see, hear, and speak from anywhere
  • 𝐓𝐰𝐨 𝐑𝐞𝐜𝐨𝐫𝐝𝐢𝐧𝐠 𝐎𝐩𝐭𝐢𝐨𝐧𝐬 & 𝐑𝐞𝐚𝐥-𝐓𝐢𝐦𝐞 𝐒𝐡𝐚𝐫𝐢𝐧𝐠 - With the mobile app, you can access the baby camera's video anytime, anywhere, view real-time footage, and even share monitoring content with family, keeping you informed about your home dynamics while you're away.Enjoy secure cloud recording with Vimtag Cloud (subscription required) for detecting people, sounds, motion. Alternatively, you can insert a microSD card (sold separately) for local video storage

CISA’s January 26, 2021 revised advisory details four CVEs affecting specified Treck HTTP Server, IPv6, and DHCPv6 components at version 6.0.1.67 and earlier. Its CVSS v3 scores belong to those listed CVEs, not to every Ripple20 vulnerability:

CVE CVSS v3 score
CVE-2020-25066 9.8 (CISA, January 26, 2021)
CVE-2020-27337 9.1 (CISA, January 26, 2021)
CVE-2020-27338 5.9 (CISA, January 26, 2021)
CVE-2020-27336 3.7 (CISA, January 26, 2021)

Does “Millions of IoT Devices” mean millions are confirmed vulnerable?

No global device count is established by the sources cited here. “Millions” should be treated as headline framing, not a verified count of affected or exploitable devices. CERT/CC notes that limited visibility into product supply chains and differences in build and runtime options make it difficult to determine impact across products.

The number of vulnerabilities, or evidence that a manufacturer used Treck software, does not by itself establish whether a particular device includes an affected component, whether the relevant feature is enabled, or whether an attacker can reach it. Vendor statements tied to a specific model and software build are more useful for determining exposure.

Is my device affected by Ripple20?

Start with the device maker, not a generic list of products said to use Treck. A manufacturer may use different components, code versions, configurations, and fixes across product families or firmware releases. Cisco’s June 2020 advisory, for example, limits its known impact to products listed as vulnerable and directs customers to product-specific fixed releases and bug details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
eufy Security SoloCam S220, Solar Security Camera, Wireless Camera Outdoor
  • Continuously Powered by Solar: Just 3 hours of sunlight is enough to keep the camera running. The tiny size and wire-free design allow it to be installed anywhere.
  • Day and Night Clarity: Enjoy clear black-and-white night vision thanks to infrared LEDs and an f/1.6 aperture. Please note that spotlight color night vision is not supported.
  • Easy Installation: Use anywhere thanks to its tiny size and wire-free design. Drill one hole, once.
  • Human Detection: Al alerts you to anyone in your yard, whether family, a courier, or a stranger. Connect to HomeBase 3 for individual facial recognition.
  • No Monthly Fee: One-time purchase. No monthly fees or hidden costs. On-device storage and AI for complete security and transparency.
  1. Identify the product. Record the manufacturer, exact model, hardware revision if available, and the device’s role on your network. For equipment managed by an employer or service provider, ask its system owner or security team to confirm these details.
  2. Find the installed software version. Check the device’s management interface, system information, or the manufacturer’s documented method for identifying its firmware or software build. Do not assume two units with the same product name run the same release.
  3. Check the manufacturer’s security notice. Search the maker’s official support or product-security pages for Ripple20 and the relevant CVE numbers. Match the exact model and installed version against the affected-products list, fixed releases, and any stated prerequisites or configuration requirements.
  4. Confirm what applies to your configuration. Check which stack component or CVE the notice identifies and whether the relevant network feature is present and enabled. If the notice does not cover your exact model or build, ask the manufacturer or authorized support channel rather than inferring that the device is either safe or vulnerable.
  5. Record the advisory date and status. Product lists and remedy plans can change. Use the latest applicable notice, and keep a record of the version, advisory date, and guidance used for your decision.

How do I fix Ripple20?

Apply the device maker’s remedy

Install the firmware or software update that the manufacturer identifies for your exact product and follow its prerequisites and operational instructions. CERT/CC advises downstream device users to contact the device vendor. It also notes that Treck recommended updating to a latest stable stack release, citing 6.0.1.67 or later in its note; CISA’s later, component-specific advisory says Treck recommended 6.0.1.68 or later for the components it covers. These stack-version statements are not interchangeable universal fixes for every product: the device maker’s instructions determine which update applies and how to deploy it.

Before updating equipment that supports a critical process, coordinate with its system owner and follow the manufacturer’s maintenance and recovery guidance. Do not substitute a generic Treck version number for an approved device firmware release.

If no fix is available, reduce exposure while you seek a supported plan

Network controls can reduce opportunities for attack, but they do not remove vulnerable code. CISA recommends minimizing network exposure, keeping control-system devices off direct internet access, placing control networks and remote devices behind firewalls, and isolating them from business networks. It also calls for impact analysis and risk assessment before defensive measures are deployed.

Depending on the device and network, CERT/CC lists additional measures such as deep-packet inspection, rejecting malformed TCP packets, restricting IP tunneling or IP source routing, disabling IPv6 features that are not needed, normalizing DNS, and applying DHCP or DHCPv6 security features. It also points to Suricata decoder-event rules for detecting attempted attacks. Choose controls with the network and device owners: filtering or disabling a feature can disrupt legitimate communications, and detection is not prevention.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Energizer Connect Smart 1080p HD Outdoor Security Socket Camera with Siren Alarm, Remote Access, Motion Alerts, 2 Way Audio and Night Vision, 2.4GHz Wi-Fi, Black
  • High-definition pan and tilt camera: Capture every detail in pristine 1080p HD quality, from any angle, with the Energizer Connect security camera's 355-degree horizontal and 48-degree vertical pan and tilt capabilities.
  • Night Vision Equipped: Camera has 4 led lights and 4 IR lights that switch automatically depending on the lighting conditions, allowing you to see color at night or black and white in total darkness.
  • Two-Way Audio: Allowing you to listen and talk to the person in the video, using the built-in microphone and speaker, or siren alarm to deter intruders.
  • Flexible Storage Options: Choose cloud storage with a complimentary 30-day trial or utilize a micro SD card (up to 128GB, not included) for local recording.
  • 2.4GHz Wi-Fi Compatible: Connects to your 2.4ghz wifi network, which is the most common wifi frequency. It does not support 5ghz wifi networks.

For a device with no available fix, ask the manufacturer what supported restrictions or workarounds exist, what functions they affect, and whether a remediation plan has changed. Cisco’s 2020 advisory said its products had no workarounds that addressed the vulnerabilities; the network mitigations it referenced were not software fixes. Treat these approaches as distinct: a patch corrects the affected software, isolation limits reachability, filtering blocks selected traffic, and detection may alert on suspicious activity.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why generic product lists and old advisories can mislead

One dated example illustrates why checks must be model-specific: Siemens ProductCERT’s February 13, 2024 advisory identified two SIMATIC RTLS Gateway variants as affected by CVE-2020-11896 and said no fix was planned at that time. That statement records the vendor’s status on that date; it does not establish the product’s status in 2026. Check for a newer Siemens notice before making a current remediation decision.

When comparing vendor responses, look for the exact model and hardware revision, firmware build, applicable CVEs or stack components, and any feature or configuration conditions. Then confirm whether the vendor has a tested fixed release, whether it requires operational changes, and—if no patch exists—whether the vendor supports a workaround or network restriction. The advisory date matters because affected lists and remediation status can change.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.