Out-of-Bounds Write Vulnerability in lwIP TCP/IP Stack MQTT
CVE-2026-87121

9.3CRITICAL

Key Information:

Vendor

Lwip

Vendor
CVE Published:
22 September 2026

What is CVE-2026-87121?

The lwIP TCP/IP Stack MQTT component is susceptible to an out-of-bounds write vulnerability. This flaw could potentially allow an attacker to exploit the stack, resulting in unauthorized code execution on impacted devices. Organizations utilizing the lwIP stack should ensure they apply the necessary updates to mitigate potential security risks associated with this vulnerability.

Affected Version(s)

TCP/IP Stack MQTT 2.0.1 <= 2.2.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shahriyar Jalayeri of ByteRay Ltd. reported this vulnerability to CISA.
.