IM
IronMonkey Threat Research
‹ Back to ICS Advisories

lwIP TCP/IP Stack MQTT Client Application

CRITICAL
CVSS 9.8
Date 2026-09-22T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-87121 9.8 critical
The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

// Remediations (1)

Mitigation: Users of lwIP are encouraged to update their version of lwIP using the repository found at https://s
Users of lwIP are encouraged to update their version of lwIP using the repository found at https://savannah.nongnu.org/projects/lwip. The commit identifier that contains the fix is f89407ea711879c04d91c92b35d67be78bbaf0f1.

// References