Skip to content
Threat Feed
critical advisory

Buffer Overflow Vulnerability in Savannah lwIP SMTP Client

A critical buffer overflow vulnerability (CVE-2026-15340) in Savannah lwIP SMTP client 2.2.1 allows unauthenticated remote attackers to trigger denial-of-service or potential remote code execution.

The Savannah lwIP SMTP client version 2.2.1 contains a critical security flaw identified as CVE-2026-15340. The vulnerability stems from improper bounds checking when processing input data, which leads to a classic buffer overflow condition. This issue is rated with a CVSS v3.1 score of 9.8, reflecting its high impact and ease of exploitability. A remote, unauthenticated attacker can leverage this weakness by sending a specially crafted packet to the vulnerable SMTP client, which resides within industrial control systems (ICS). Successful exploitation results in either an immediate service crash, leading to a denial-of-service (DoS) condition, or the execution of arbitrary code with the privileges of the underlying SMTP process. Given the deployment of these devices in critical infrastructure sectors like Energy and Water, this flaw presents a significant risk to operational technology (OT) environments.

Impact

The vulnerability affects lwIP SMTP client 2.2.1, which is deployed globally across the Energy and Water and Wastewater systems sectors. If successfully exploited, an attacker can disable essential monitoring or control devices, disrupting critical utility operations. Remote code execution could allow for persistent compromise of the control system environment, potentially leading to unauthorized manipulation of industrial processes or deeper lateral movement into sensitive segments of the OT network.

Recommendation

Prioritized actions for security teams managing affected Savannah lwIP infrastructure:

  • Apply the vendor-provided mitigation by integrating the fix released in patch_125_smtp_txbuf.diff or updating to the commit referenced (614420f82c8729d070e01464c0dddb3c9525c772).
  • Immediately isolate all devices running the affected lwIP SMTP client version 2.2.1 from the public internet to mitigate the risk of remote unauthenticated exploitation.
  • Enforce strict network segmentation for all control system networks, placing sensitive devices behind firewalls and ensuring they are isolated from enterprise IT networks.
  • Require the use of hardened, VPN-based remote access for any necessary management of these assets, ensuring all remote access infrastructure is updated and monitored for unauthorized usage.

Immediate actions

Isolate devices running lwIP SMTP client 2.2.1 from the internet

IT Operations 24h

Mitigations

Apply patch_125_smtp_txbuf.diff or commit 614420f82c8729d070e01464c0dddb3c9525c772

immediate IT Operations

CVE-2026-15340