lwIP TCP/IP Stack MQTT Client Application

Summary

The lwIP TCP/IP Stack MQTT Client Application versions 2.0.1 through 2.2.1 are affected by an out-of-bounds write vulnerability (CVE-2026-87121). Successful exploitation could allow an attacker to gain full code execution on the affected device.

IFF Assessment

FOE

This vulnerability allows attackers to achieve full code execution, posing a significant threat to targeted systems.

Severity

9.8 Critical

The CVSS v3.1 score of 9.8 (CRITICAL) is based on a vector string indicating Network attack vector (AV:N), Low attack complexity (AC:L), No privileges required (PR:N), No user interaction (UI:N), Unchanged scope (S:U), High confidentiality (C:H), High integrity (I:H), and High availability (A:H) impact, stemming from an out-of-bounds write.

Defender Context

Defenders should prioritize patching or mitigating this critical vulnerability in systems utilizing the lwIP TCP/IP Stack MQTT Client Application. The widespread use of this stack in critical infrastructure sectors worldwide underscores the urgency of addressing this out-of-bounds write flaw, which could lead to complete device compromise.

Read Full Story →