External risk intelligence

lwIP MQTT Out-of-Bounds Write Allows Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-87121

lwIP is a lightweight TCP/IP stack used in embedded IoT and industrial devices. While the MQTT component can be exposed to the internet, it is typically deployed within internal or restricted machine-to-machine networks. Public internet exposure is possible but not the standard default for most implementations.

Out-of-bounds Write

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

The lwIP TCP/IP stack, specifically its MQTT component, has a vulnerability that could allow an unauthorized party to gain complete control over a device. This matters because it affects technologies used in IoT and industrial settings, where even a single compromised device can have broader implications. The primary concern is to determine if this technology is in use and if it is exposed in a way that could be targeted.

  • Out-of-bounds write in lwIP MQTT.
  • Critical risk to device control and code execution.
  • Confirm relevance and exposure of affected systems.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted network traffic to a device running the lwIP TCP/IP stack with MQTT enabled. Since the vulnerability is in the MQTT component, the attacker would need network access to reach this service. Successful exploitation could lead to the attacker gaining full code execution on the affected device.

  • No specific access or authentication is required.
  • Triggered by sending malformed MQTT network traffic.
  • Risk of full code execution on the device.

Live Threat

Current exploitation, exposure, and threat context

The lwIP TCP/IP Stack MQTT component is susceptible to an out-of-bounds write vulnerability. When supported by the advisory, this could allow an attacker to achieve full code execution on the affected device.

  • Device code execution could be compromised.
  • Exploitation may occur via network access.
  • Full control over the device is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the lwIP TCP/IP stack's MQTT component requires action from teams managing embedded devices and IoT infrastructure. The initial step is to locate all instances of the affected technology, assess their exposure and criticality, and identify the responsible system owners before planning any remediation efforts.

  • Identify asset owners and criticality.
  • Verify MQTT network exposure.
  • Plan coordinated remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the lwIP TCP/IP stack?

lwIP is a compact, lightweight networking stack designed specifically for embedded systems, IoT devices, and industrial controllers. It provides the core functionality needed for these resource-constrained devices to connect to networks using common protocols like MQTT for messaging, allowing them to communicate efficiently in environments where full-featured operating systems are too large or impractical.

What does CVE-2026-87121 mean for a device?

This vulnerability is classified as an out-of-bounds write (CWE-787). In simple terms, it means the MQTT component fails to properly check the size of incoming data, allowing it to write information into parts of the device's memory it shouldn't touch. This error can be leveraged to overwrite critical instructions, potentially giving an attacker full control or the ability to execute unauthorized code on the device.

How is this vulnerability triggered?

An attacker triggers this by sending malformed or specially crafted MQTT network packets to an affected device. The vulnerability exists specifically within the processing of this traffic. It is important to note that sending standard, well-formed MQTT messages or traffic directed at other services on the device will not trigger this specific memory corruption bug.

Is my device at risk based on Halo Surface Signal?

The risk depends on how your device is networked. According to Halo Surface Signal, while the MQTT component can be exposed to the public internet, it is most commonly deployed within internal or restricted machine-to-machine networks. If your system is isolated from the internet, the likelihood of an external attacker reaching the vulnerable service is significantly lower than for publicly accessible devices.

What should I do first to address this?

Begin by identifying all hardware or firmware in your environment that utilizes the lwIP stack with the MQTT component enabled. Once identified, map these assets to their owners and determine their specific network placement. Prioritize evaluating devices that are connected to broader networks, as these represent the most immediate path for potential interaction.

References