IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Savannah lwIP SMTP client

CRITICAL
CVSS 9.8
Date 2026-10-06T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-15340 9.8 critical
lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.

// Remediations (1)

Mitigation: xchglabs reports that the vulnerability was fixed and released in the following patch: patch_125_smt
xchglabs reports that the vulnerability was fixed and released in the following patch: patch_125_smtp_txbuf.diff . This is available as available as git commit (614420f82c8729d070e01464c0dddb3c9525c772)

// References