{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/lwip-tcp/ip-stack-mqtt-client-application-2.0.1---2.2.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lwip:lwip:2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:lwip:lwip:2.2.1:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["lwIP TCP/IP Stack MQTT Client Application (2.0.1 - 2.2.1)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["lwIP"],"content_html":"\u003cp\u003eThe lwIP TCP/IP stack contains a critical out-of-bounds write vulnerability in its MQTT client implementation, tracked as CVE-2026-87121. This flaw affects versions 2.0.1 through 2.2.1 of the MQTT client application. The vulnerability allows an unauthenticated, remote attacker to trigger a memory corruption condition by sending specially crafted MQTT packets, potentially leading to full code execution on the underlying device. Given that the lwIP stack is commonly embedded in resource-constrained IoT, industrial, and embedded devices across critical infrastructure sectors such as energy, water, and manufacturing, this vulnerability presents a high risk for wide-scale exploitation. Defenders should prioritize identifying instances of the affected stack within their OT and IoT environments and apply the upstream patch associated with commit f89407ea711879c04d91c92b35d67be78bbaf0f1.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-87121 allows an unauthenticated remote attacker to gain full code execution on the device, resulting in a complete compromise of the affected asset. This could lead to unauthorized control of industrial processes, exfiltration of sensitive telemetry data, or deployment of further payloads. The vulnerability is rated with a CVSS score of 9.8 (Critical) due to its remote, unauthenticated, and low-complexity exploitation requirements. Sectors relying on embedded lwIP stacks, particularly those in critical infrastructure, face significant operational and security risks if devices are exposed to untrusted networks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately identify all systems utilizing the lwIP TCP/IP Stack MQTT client version 2.0.1 through 2.2.1.\u003c/li\u003e\n\u003cli\u003eApply the official vendor fix available in the lwIP project repository, specifically the commit f89407ea711879c04d91c92b35d67be78bbaf0f1.\u003c/li\u003e\n\u003cli\u003eIsolate vulnerable devices from the public internet by placing them behind firewalls or within dedicated, restricted network segments.\u003c/li\u003e\n\u003cli\u003eImplement network-level ingress filtering to restrict MQTT traffic (typically port 1883 or 8883) to authorized communication partners only.\u003c/li\u003e\n\u003cli\u003eEnable logging for MQTT traffic patterns to detect anomalies indicative of malformed packet transmission.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T16:47:26Z","date_published":"2026-09-22T16:47:26Z","id":"https://feed.craftedsignal.io/briefs/2026-09-lwip-mqtt-rce/","summary":"An out-of-bounds write vulnerability (CVE-2026-87121) in the lwIP TCP/IP Stack MQTT client allows unauthenticated remote attackers to achieve full code execution on affected devices.","title":"Critical Out-of-Bounds Write in lwIP MQTT Client","url":"https://feed.craftedsignal.io/briefs/2026-09-lwip-mqtt-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - LwIP TCP/IP Stack MQTT Client Application (2.0.1 - 2.2.1)","version":"https://jsonfeed.org/version/1.1"}