CISA flags CVE-2026-15340 buffer overflow in lwIP SMTP client
Reachable over the network with no authentication, the overflow can enable remote code execution on unpatched 2.2.1 builds.
TL;DR
CISA published ICSA-26-279-02 for CVE-2026-15340, a buffer overflow in Savannah lwIP SMTP client 2.2.1 rated 9.8 critical. The attack vector is network-based with no authentication or user interaction, and success can crash the device or enable remote code execution. The advisory lists Energy and Water and Wastewater Systems as affected sectors, deployed worldwide. The fix ships as git commit 614420f82c8729d070e01464c0dddb3c9525c772 via patch_125_smtp_txbuf.diff, disclosed by xchglabs after the patch released.
On October 6, CISA published ICSA-26-279-02 for CVE-2026-15340, a buffer overflow in the Savannah lwIP SMTP client version 2.2.1. CISA catalogs it as CWE-120, Buffer Copy without Checking Size of Input, and rates it 9.8 critical under CVSS 3.1, with a network attack vector, low complexity, no privileges required, and no user interaction. Successful exploitation can crash the device or, per the advisory, allow remote code execution.
The background section lists Energy and Water and Wastewater Systems as the affected critical infrastructure sectors, with worldwide deployment. Operators don't get a packaged update here; the fix is the source-level patch file patch_125_smtp_txbuf.diff, available as git commit 614420f82c8729d070e01464c0dddb3c9525c772. xchglabs reported the flaw to Savannah and disclosed it after the fix was released.
CISA's recommended practices for this advisory follow the standard ICS playbook: minimize network exposure for control systems, keep them isolated behind firewalls, and use VPNs where remote access is unavoidable while recognizing VPNs carry their own vulnerabilities.
Published ·Deep Fathom