VDB

CVE-2026-8836

CVE-2026-8836 PUBLISHED CVSS 10 CRITICAL

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameters results in stack-based buffer overflow. The attack may be initiated remotely. The patch is named 0c957ec03054eb6c8205e9c9d1d05d90ada3898c. It is suggested to install a patch to address this issue.

EPSS 1.10% · 64.1th percentile

Risk Scores

CVSS 2.0
10
EPSS Score
1.10%
64.1th percentile

Affected Products

VendorProductVersions
n/alwIP2.1.0, 2.1.1, 2.1.2

Timeline

  • May 18, 2026 PoC Published
  • May 18, 2026 CVE Published
  • May 18, 2026 PoC Published
  • May 19, 2026 EPSS Score
  • May 19, 2026 Coalition ESS Score
  • May 19, 2026 PoC Published
  • May 19, 2026 Security Advisory
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›