Savannah lwIP SMTP client

Summary

A critical vulnerability (CVE-2026-15340) has been identified in Savannah's lwIP SMTP client versions prior to 2.2.1, where a buffer overflow condition could lead to remote code execution or device crashes. The vulnerability stems from the client failing to check the size of input data. This flaw affects critical infrastructure sectors like energy and water, with a worldwide deployment.

IFF Assessment

FOE

This vulnerability allows for remote code execution and device crashes, posing a significant threat to critical infrastructure and impacting defenders.

Severity

9.8 Critical

The CVSS score of 9.8 (CRITICAL) indicates a severe vulnerability. The vector string (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) highlights that it is network-exploitable with low complexity, no privileges required, no user interaction, and high impacts on confidentiality, integrity, and availability.

Defender Context

This vulnerability represents a critical threat to operational technology (OT) systems, particularly in sectors like energy and water. Defenders should prioritize patching or mitigating this flaw, as it allows for unauthenticated remote code execution which could disrupt essential services. Monitoring for exploitation attempts and ensuring robust network segmentation for OT environments are crucial.

Read Full Story →