{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/lwip/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lwip:lwip:2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:lwip:lwip:2.2.1:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["lwIP TCP/IP Stack MQTT Client Application (2.0.1 - 2.2.1)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["lwIP"],"content_html":"\u003cp\u003eThe lwIP TCP/IP stack contains a critical out-of-bounds write vulnerability in its MQTT client implementation, tracked as CVE-2026-87121. This flaw affects versions 2.0.1 through 2.2.1 of the MQTT client application. The vulnerability allows an unauthenticated, remote attacker to trigger a memory corruption condition by sending specially crafted MQTT packets, potentially leading to full code execution on the underlying device. Given that the lwIP stack is commonly embedded in resource-constrained IoT, industrial, and embedded devices across critical infrastructure sectors such as energy, water, and manufacturing, this vulnerability presents a high risk for wide-scale exploitation. Defenders should prioritize identifying instances of the affected stack within their OT and IoT environments and apply the upstream patch associated with commit f89407ea711879c04d91c92b35d67be78bbaf0f1.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-87121 allows an unauthenticated remote attacker to gain full code execution on the device, resulting in a complete compromise of the affected asset. This could lead to unauthorized control of industrial processes, exfiltration of sensitive telemetry data, or deployment of further payloads. The vulnerability is rated with a CVSS score of 9.8 (Critical) due to its remote, unauthenticated, and low-complexity exploitation requirements. Sectors relying on embedded lwIP stacks, particularly those in critical infrastructure, face significant operational and security risks if devices are exposed to untrusted networks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately identify all systems utilizing the lwIP TCP/IP Stack MQTT client version 2.0.1 through 2.2.1.\u003c/li\u003e\n\u003cli\u003eApply the official vendor fix available in the lwIP project repository, specifically the commit f89407ea711879c04d91c92b35d67be78bbaf0f1.\u003c/li\u003e\n\u003cli\u003eIsolate vulnerable devices from the public internet by placing them behind firewalls or within dedicated, restricted network segments.\u003c/li\u003e\n\u003cli\u003eImplement network-level ingress filtering to restrict MQTT traffic (typically port 1883 or 8883) to authorized communication partners only.\u003c/li\u003e\n\u003cli\u003eEnable logging for MQTT traffic patterns to detect anomalies indicative of malformed packet transmission.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T16:47:26Z","date_published":"2026-09-22T16:47:26Z","id":"https://feed.craftedsignal.io/briefs/2026-09-lwip-mqtt-rce/","summary":"An out-of-bounds write vulnerability (CVE-2026-87121) in the lwIP TCP/IP Stack MQTT client allows unauthenticated remote attackers to achieve full code execution on affected devices.","title":"Critical Out-of-Bounds Write in lwIP MQTT Client","url":"https://feed.craftedsignal.io/briefs/2026-09-lwip-mqtt-rce/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["lwIP (Lightweight IP) (\u003e=2.0.1, \u003c=2.2.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["lwIP"],"content_html":"\u003cp\u003elwIP (Lightweight IP) is a widely deployed open-source TCP/IP stack intended for embedded systems. A double free vulnerability, identified as CVE-2026-91018, exists in the API implementation of lwIP versions 2.0.1 through 2.2.1. This vulnerability arises from improper handling of memory allocation, specifically a double free condition (CWE-415). An attacker capable of sending specifically crafted packets from an adjacent network segment can exploit this flaw. Successful exploitation can lead to a system crash, denial of service, memory corruption, or arbitrary code execution on the target device. Given the widespread use of lwIP in critical infrastructure sectors - including energy, water, healthcare, and industrial control systems - this vulnerability poses a significant risk to the integrity and availability of embedded network hardware.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-91018 can result in complete system compromise or persistent denial of service in embedded devices. Because lwIP is integrated into numerous industrial and communications products globally, the scope of potentially vulnerable assets is extensive across critical infrastructure sectors such as energy, water, and manufacturing. If exploited, an attacker could achieve arbitrary code execution, bypassing safety controls or exfiltrating sensitive operational data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the lwIP library to a patched version using the source repository provided at \u003ca href=\"https://cgit.git.savannah.gnu.org/cgit/lwip.git\"\u003ehttps://cgit.git.savannah.gnu.org/cgit/lwip.git\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eApply the specific fix identified by commit hash f873b6295933e4149a2132adf3e9a2d2a676a5ec.\u003c/li\u003e\n\u003cli\u003eIsolate embedded control system devices from business networks and ensure they are not directly accessible via the public internet.\u003c/li\u003e\n\u003cli\u003eImplement network-level segmentation to restrict access to the affected devices, limiting communication to authorized, trusted adjacent network segments only.\u003c/li\u003e\n\u003cli\u003eDeploy VPNs for required remote access, ensuring the VPN infrastructure itself is patched and hardened against exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T16:46:52Z","date_published":"2026-09-22T16:46:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-lwip-double-free/","summary":"The lwIP TCP/IP stack contains a double free vulnerability (CVE-2026-91018) that could allow an attacker with adjacent network access to trigger memory corruption or remote code execution.","title":"Double Free Vulnerability in lwIP (Lightweight IP)","url":"https://feed.craftedsignal.io/briefs/2026-09-lwip-double-free/"}],"language":"en","title":"CraftedSignal Threat Feed - LwIP","version":"https://jsonfeed.org/version/1.1"}