vulnerability
Published 2026-10-06
Verified 2026-10-10

lwIP SMTP client CVE-2026-15340 (CVSS 9.8): a server-driven AUTH reply overflows the transmit buffer in the embedded TCP/IP stack's optional SMTP client, risking crashes or code execution on energy and water devices; fixed only in a git commit, no new lwIP release

CISA published ICS advisory ICSA-26-279-02 on 6 October 2026 for the SMTP client application shipped with lwIP, the lightweight open-source TCP/IP stack (hosted on Savannah) that is compiled into a huge range of microcontroller and embedded products. CISA lists lwIP SMTP client 2.2.1 as affected and says the client does not check the size of its inputs, so a buffer overflow can crash the device and may allow remote code execution; it lists energy and water and wastewater as the critical infrastructure sectors and says deployments are worldwide. CVE-2026-15340 was published to the CVE list on 9 October with a CVSS 3.1 score of 9.8 (CVSS 4.0 9.3). The fix, credited to xchglabs and committed to lwIP's git repository by maintainer Simon Goldschmidt on 12 May 2026 as 'smtp: fix server-driven AUTH line overflow into tx_buf' (bug #68313, commit 614420f), changes only src/apps/smtp/smtp.c, which means the overflow is triggered by the mail server's side of an AUTH exchange and only matters for firmware that builds and uses the SMTP client module. CISA's decision data marks exploitation as proof-of-concept, with no reports of attacks. Because lwIP is embedded inside vendors' firmware, most owners cannot patch it themselves and need a firmware update from the device maker. Primary: CISA advisory; vendor: lwIP fix commit.

Product
lwIP (lightweight IP) embedded TCP/IP stack — SMTP client application (src/apps/smtp)
Versions
lwIP SMTP client 2.2.1 (per CISA); builds without commit 614420f
CVSS
(CVSS 3.1); 9.3 (CVSS 4.0) — CISA
Exploited in Australia?
unknown
Patch to
Firmware developers: apply lwIP commit 614420f (patch_125_smtp_txbuf) or disable the SMTP client module if unused, then ship updated firmware. Asset owners: ask device vendors whether their firmware uses lwIP's SMTP client and when a fix is due; meanwhile point device email alerts only at a trusted internal relay, block outbound SMTP from OT devices to the internet, and keep control-system devices off the internet behind firewalls.

Primary: CISA ICS advisory ICSA-26-279-02 — Savannah lwIP SMTP client (6 Oct 2026) · Vendor: lwIP git commit 614420f — smtp: fix server-driven AUTH line overflow into tx_buf (bug #68313) · CVE: CVE-2026-15340 · CISA CSAF — icsa-26-279-02.json

vulnerabilities ot ics network