CVE-2026-87121: Out-of-bounds write in lwIP TCP/IP Stack MQTT Client Application Out-of-bounds write
Published Sep 22, 2026
·Updated
lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.
Affected Software
1 affected component
lwIP lwIP TCP/IP Stack MQTT Client Application
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
lwIP TCP/IP Stack MQTTto a version that resolves this vulnerability.Patch f89407ea711879c04d91c92b35d67be78bbaf0f1
Event History
Sep 22, 2026
CVE Published
via MITRE·07:48 PM
Data Sourced
via MITRE·07:48 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The CVSS vector indicates network access is sufficient; no prior privileges or user interaction are required. The attack complexity is rated low.
2
Which deployments are most exposed?
Devices running the affected lwIP MQTT client application that are reachable over a network are the relevant exposure set. The available information does not state whether the vulnerable behavior is enabled in a default configuration.