CISA

Savannah lwIP SMTP client

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution.

The following versions of Savannah lwIP SMTP client are affected:

lwIP SMTP client 2.2.1 (CVE-2026-15340)

Vendor

Equipment

Savannah

lwIP SMTP client

1 Vulnerability

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Critical Infrastructure Sectors: Energy, Water and Wastewater Systems

Countries/Areas Deployed: Worldwide

Company Headquarters Location: Sweden

lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.

Read More

1 Affected Product

Savannah lwIP SMTP client: 2.2.1

Mitigationxchglabs reports that the vulnerability was fixed and released in the following patch: patch_125_smtp_txbuf.diff . This is available as available as git commit (614420f82c8729d070e01464c0dddb...