<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>LwIP SMTP Client (2.2.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/lwip-smtp-client-2.2.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 17:12:16 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/lwip-smtp-client-2.2.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Buffer Overflow Vulnerability in Savannah lwIP SMTP Client</title><link>https://feed.craftedsignal.io/briefs/2026-10-savannah-lwip-smtp/</link><pubDate>Tue, 06 Oct 2026 17:12:16 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-savannah-lwip-smtp/</guid><description>A critical buffer overflow vulnerability (CVE-2026-15340) in Savannah lwIP SMTP client 2.2.1 allows unauthenticated remote attackers to trigger denial-of-service or potential remote code execution.</description><content:encoded><![CDATA[<p>The Savannah lwIP SMTP client version 2.2.1 contains a critical security flaw identified as CVE-2026-15340. The vulnerability stems from improper bounds checking when processing input data, which leads to a classic buffer overflow condition. This issue is rated with a CVSS v3.1 score of 9.8, reflecting its high impact and ease of exploitability. A remote, unauthenticated attacker can leverage this weakness by sending a specially crafted packet to the vulnerable SMTP client, which resides within industrial control systems (ICS). Successful exploitation results in either an immediate service crash, leading to a denial-of-service (DoS) condition, or the execution of arbitrary code with the privileges of the underlying SMTP process. Given the deployment of these devices in critical infrastructure sectors like Energy and Water, this flaw presents a significant risk to operational technology (OT) environments.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability affects lwIP SMTP client 2.2.1, which is deployed globally across the Energy and Water and Wastewater systems sectors. If successfully exploited, an attacker can disable essential monitoring or control devices, disrupting critical utility operations. Remote code execution could allow for persistent compromise of the control system environment, potentially leading to unauthorized manipulation of industrial processes or deeper lateral movement into sensitive segments of the OT network.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams managing affected Savannah lwIP infrastructure:</p>
<ul>
<li>Apply the vendor-provided mitigation by integrating the fix released in patch_125_smtp_txbuf.diff or updating to the commit referenced (614420f82c8729d070e01464c0dddb3c9525c772).</li>
<li>Immediately isolate all devices running the affected lwIP SMTP client version 2.2.1 from the public internet to mitigate the risk of remote unauthenticated exploitation.</li>
<li>Enforce strict network segmentation for all control system networks, placing sensitive devices behind firewalls and ensuring they are isolated from enterprise IT networks.</li>
<li>Require the use of hardened, VPN-based remote access for any necessary management of these assets, ensuring all remote access infrastructure is updated and monitored for unauthorized usage.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>critical-infrastructure</category><category>buffer-overflow</category><category>industrial-control-systems</category><category>ot-security</category></item></channel></rss>