Skip to finding
important · Firmware — MQTT

A malicious MQTT peer can overrun the receive buffer in lwIP-based firmware.

Affects

lwIP MQTT Client Application, a lightweight TCP/IP component compiled into embedded, IoT and industrial device firmware.

An oversized or malformed MQTT header can advance msg_idx beyond the fixed receive-buffer limit and write attacker-supplied bytes into adjacent memory.

Detail and 3 sources

The attacker must control or intercept the broker connection; the memory corruption is confirmed, but controlled execution on a shipping device and the downstream product population remain unproven.

Upstream now bounds msg_idx before the write and tests malformed input.

Chain to watch
Control or intercept the device's MQTT broker connection→↓Return an oversized or malformed MQTT header→↓Write attacker-controlled bytes beyond the fixed receive buffer→↓Controlled code execution on a shipping device and the population of affected downstream products remain unproven.
Unverified chainDemonstrate controlled execution on a shipping device using the affected lwIP MQTT client, then identify the firmware task's privilege and hardening context.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 23, 2026