{"id":"CVE-2026-87121","published":"2026-09-22T20:17:09.967","lastModified":"2026-09-23T19:42:48.540","description":"lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-787"],"vendors":[],"products":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-01.json","tags":[]},{"url":"https://savannah.nongnu.org/projects/lwip","tags":[]},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-01","tags":[]}],"exploitRefs":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-01.json","tags":[]}],"hasPoc":true,"ai":{"summary":"The lwIP TCP/IP Stack MQTT implementation is vulnerable to an out-of-bounds write, enabling full code execution on the device. This flaw is critical as it allows attackers to gain control over the device.","exploitability":"Exploitation requires network access and knowledge of the affected MQTT implementation. Precondition is the presence of the vulnerable lwIP version and active MQTT communication.","blast_radius":"If exploited, the attacker could gain full control over the device, leading to potential data theft, device compromise, or further attacks.","remediation":"Upgrade to the lwIP version 2.1.3 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","network","tcp/ip","mqtt"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:50:27.190Z"}}