A critical vulnerability (CVE-2026-15340) with a CVSS score of 9.8 has been identified in Savannah lwIP SMTP client version 2.2.1, which does not check the size of inputs potentially allowing a buffer overflow; successful exploitation could crash the device being accessed and may allow remote code execution via the environment template management API, requiring no user interaction or privileges, impacting business operations by disrupting critical infrastructure sectors such as Energy, Water and Wastewater Systems worldwide. This flaw type is classified as Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') with an attack vector of Network (AV:N) and a base severity of CRITICAL. The vulnerability may allow an attacker to execute arbitrary code on the affected system, potentially leading to unauthorized access or data theft. To mitigate this issue, users are advised to minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet, locate control system networks and remote devices behind firewalls and isolating them from business networks, and use more secure methods such as virtual private networks (VPNs) when remote access is required. It is essential for organizations to perform proand risk assessment prior to deploying defensive measures.
We recommend you to update Savannah lwIP SMTP client to git commit (614420f82c8729d070e01464c0dddb3c9525c772).[/subscribe_to_unlock_form]
A critical vulnerability (CVE-2026-15340) with a CVSS score of 9.8 has been identified in Savannah lwIP SMTP client version 2.2.1, which does not check the size of inputs potentially allowing a buffer overflow; successful exploitation could crash the device being accessed and may allow remote code execution via the environment template management API, requiring no user interaction or privileges, impacting business operations by disrupting critical infrastructure sectors such as Energy, Water and Wastewater Systems worldwide. This flaw type is classified as Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') with an attack vector of Network (AV:N) and a base severity of CRITICAL. The vulnerability may allow an attacker to execute arbitrary code on the affected system, potentially leading to unauthorized access or data theft. To mitigate this issue, users are advised to minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet, locate control system networks and remote devices behind firewalls and isolating them from business networks, and use more secure methods such as virtual private networks (VPNs) when remote access is required. It is essential for organizations to perform proand risk assessment prior to deploying defensive measures.
We recommend you to update Savannah lwIP SMTP client to git commit (614420f82c8729d070e01464c0dddb3c9525c772).[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]