EPSS 0.01 (nejvyšší)
lwIP - Multiple Severe Vulnerabilities
Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-87121, CVE-2026-91018, Summary: Two memory-safety vulnerabilities affect lwIP versions 2.0.1–2.2.1. CVE-2026-87121 is an out-of-bounds write in the MQTT client that could allow an unauthenticated network attacker to execute code on an affected device. CVE-2026-91018 is an adjacent-network double-free vulnerability that could cause denial of service, memory corruption or code execution…
lwIP FI
CVE v události 2
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-87121 | 9.8 3.1 · icscert 9.3 4.0 · icscert | – | 0.01 |
| CVE-2026-91018 | 8.8 3.1 · icscert 8.7 4.0 · icscert | – | 0.00 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.