CVE-2020-11896

CRITICAL

Treck TCP/IP < 6.0.1.66 - Remote Code Execution via IPv4 Tunneling

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2020-11896. PoCs published by Fans0n-Fan, 0xkol.

AI-analyzed exploit summary This repository contains a scanner for detecting devices using the Treck TCP/IP stack by sending custom ICMP packets (type 0xa5) and checking for specific responses. It also includes a PoC for CVE-2020-11896, which sends malformed UDP packets to trigger a potential vulnerability.

Description

The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.

Exploits (2)

nomisec SCANNER 10 stars
by Fans0n-Fan · poc
https://github.com/Fans0n-Fan/Treck20-Related

This repository contains a scanner for detecting devices using the Treck TCP/IP stack by sending custom ICMP packets (type 0xa5) and checking for specific responses. It also includes a PoC for CVE-2020-11896, which sends malformed UDP packets to trigger a potential vulnerability.

Classification
Scanner 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Theoretical
Target: Treck TCP/IP stack
No auth needed
Prerequisites: Network access to target device · Scapy library installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 8 stars
by 0xkol · poc
https://github.com/0xkol/ripple20-digi-connect-exploit

This is a functional PoC exploit for CVE-2020-11896, targeting a heap-based buffer overflow in the Treck TCP/IP stack (Ripple20) on Digi Connect ME 9210 devices. It achieves remote code execution via a multi-stage attack involving ICMP and UDP packet manipulation.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Digi Connect ME 9210 running NET+OS 7.5
No auth needed
Prerequisites: Network access to the target device · Treck TCP/IP stack vulnerability presence
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://www.kb.cert.org/vuls/id/257161/
Product, Vendor Advisory x_refsource_misc
https://www.treck.com
Third Party Advisory x_refsource_misc
https://jsof-tech.com/vulnerability-disclosure-policy/
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
https://www.kb.cert.org/vuls/id/257161
Exploit, Third Party Advisory x_refsource_misc
https://www.jsof-tech.com/ripple20/
Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20200625-0006/

Scores

CVSS v3 10.0
EPSS 0.3696
EPSS Percentile 98.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-119 CWE-787
Status published
Products (1)
treck/tcp\/ip < 6.0.1.66
Published Jun 17, 2020
Tracked Since Feb 18, 2026