A malicious MQTT peer can overrun the receive buffer in lwIP-based firmware.
Affects
lwIP MQTT Client Application, a lightweight TCP/IP component compiled into embedded, IoT and industrial device firmware.
An oversized or malformed MQTT header can advance msg_idx beyond the fixed receive-buffer limit and write attacker-supplied bytes into adjacent memory.
Detail and 3 sources
The attacker must control or intercept the broker connection; the memory corruption is confirmed, but controlled execution on a shipping device and the downstream product population remain unproven.
Upstream now bounds msg_idx before the write and tests malformed input.
Chain to watch
Control or intercept the device's MQTT broker connection→↓Return an oversized or malformed MQTT header→↓Write attacker-controlled bytes beyond the fixed receive buffer→↓Controlled code execution on a shipping device and the population of affected downstream products remain unproven.
Unverified chainDemonstrate controlled execution on a shipping device using the affected lwIP MQTT client, then identify the firmware task's privilege and hardening context.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.