Description
lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.
Published: 2026-09-22
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Full Code Execution
Action: Immediate Patch
AI Analysis

Impact

An out‑of‑bounds write occurs in the lwIP TCP/IP Stack MQTT client, a flaw that allows a remote adversary to overwrite memory beyond an expected boundary. Exploiting this vulnerability can grant the attacker arbitrary code execution, effectively enabling complete takeover of the affected device and compromising its confidentiality, integrity, and availability.

Affected Systems

The vulnerability resides in the lwIP TCP/IP Stack MQTT, a networking component used in various embedded and industrial control systems. The listing does not provide explicit version ranges, but any instance employing lwIP prior to the fix commit is susceptible.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical severity, and the EPSS score is currently not available, making it difficult to gauge real‑world exploitation momentum. The flaw is not listed in the CISA KEV catalog, suggesting no confirmed large‑scale exploits yet. Based on the description, the likely attack path involves an attacker sending a maliciously crafted MQTT packet to a device that uses the vulnerable lwIP stack, triggering the out‑of‑bounds write and thus achieving code execution.

Generated by OpenCVE AI on September 22, 2026 at 21:31 UTC.

Remediation

Vendor Solution

Users of lwIP are encouraged to update their version of lwIP using the repository found at  https://savannah.nongnu.org/projects/lwip . The commit identifier that contains the fix is f89407ea711879c04d91c92b35d67be78bbaf0f1.


OpenCVE Recommended Actions

  • Upgrade lwIP to the patched version containing commit f89407ea711879c04d91c92b35d67be78bbaf0f1 from https://savannah.nongnu.org/projects/lwip
  • If an immediate upgrade is not possible, block or restrict inbound MQTT traffic to the device until the patch can be applied
  • Implement MQTT input validation or disable the MQTT client layer until the vulnerability is resolved

Generated by OpenCVE AI on September 22, 2026 at 21:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.
Title Out-of-bounds write in lwIP TCP/IP Stack MQTT Client Application
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-22T20:23:09.069Z

Reserved: 2026-09-09T21:28:27.099Z

Link: CVE-2026-87121

cve-icon Vulnrichment

Updated: 2026-09-22T20:23:05.983Z

cve-icon NVD

Status : Received

Published: 2026-09-22T20:17:09.967

Modified: 2026-09-22T21:17:32.930

Link: CVE-2026-87121

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:45:06Z

Weaknesses