← Back to search

CVE-2026-87121

9.8 CRITICALpublic exploit available

Published 2026-09-22 · Updated 2026-09-23

AI risk analysis

Summary
The lwIP TCP/IP Stack MQTT implementation is vulnerable to an out-of-bounds write, enabling full code execution on the device. This flaw is critical as it allows attackers to gain control over the device.
Exploitability
Exploitation requires network access and knowledge of the affected MQTT implementation. Precondition is the presence of the vulnerable lwIP version and active MQTT communication.
Blast radius
If exploited, the attacker could gain full control over the device, leading to potential data theft, device compromise, or further attacks.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the lwIP version 2.1.3 or later.
rcenetworktcp/ipmqtt

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-787

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.