← back
CVE-2026-87121criticalCWE-787

Out-of-bounds write in lwIP TCP/IP Stack MQTT Client Application

25Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.3
exploitation probability
observed exploitation
nono source reports it
lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
lwIP · TCP/IP Stack MQTT