Security/ ics-security · lwip · buffer-overflow · critical-infrastructure

Buffer Overflow Bug Hits Open-Source SMTP Client in ICS Devices

A critical buffer overflow in lwIP's SMTP client, used in energy and water systems worldwide, could crash devices or enable remote code execution.

A critical bug in the open-source lwIP SMTP client could let attackers crash or hijack industrial control systems.

CISA disclosed CVE-2026-15340 on October 6, 2026: a classic buffer overflow in version 2.2.1 of the lwIP SMTP client that fails to check the size of inputs before copying them. The flaw scores 9.8 out of 10 on CVSS 3.1, about as severe as the scale gets. lwIP is maintained on GNU Savannah by a Sweden-based team and is deployed in control systems across the energy and water and wastewater sectors worldwide. The security group xchglabs found the bug, reported it privately to the project, and held disclosure until a patch shipped.

Exploiting the flaw can crash a device outright or, worse, let an attacker run arbitrary code on it. For a water treatment controller or an energy-grid component, neither outcome is a minor inconvenience. Because lwIP is a shared networking stack baked into many vendors' hardware rather than one company's product, the fix has to trickle down through every device maker who built on it, not just one vendor's update cycle.

The fix itself is a single patch file, not a redesign - but like most ICS bugs, it's only fixed once someone actually flashes the device.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →