---
id: CVE-2026-8836
title: A vulnerability was found in lwIP up to 2.2.1
summary: >-
  A vulnerability was found in lwIP up to 2.2.1. Affected is the function
  snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component
  snmpv3 USM Handler. Performing a manipulation of the argument
  msgAuthenticationParamet…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-121
published: '2026-05-18'
updated: '2026-08-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8836'
references:
  - url: >-
      https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=0c957ec03054eb6c8205e9c9d1d05d90ada3898c
    label: cna@vuldb.com
  - url: >-
      https://github.com/lwip-tcpip/lwip/commit/0c957ec03054eb6c8205e9c9d1d05d90ada3898c
    label: cna@vuldb.com
  - url: 'https://savannah.nongnu.org/bugs/?68055'
    label: cna@vuldb.com
  - url: 'https://savannah.nongnu.org/bugs/?68194'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-8836'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/829798'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/364474'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/364474/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - exploit-available
epss: 0.01097
epssPercentile: 0.64184
ingestedAt: '2026-08-22T12:31:57.140Z'
exploits:
  github: 1
  githubRepos:
    - >-
      https://github.com/Hunt-Benito/lwip-snmpv3-stack-overflow-cve-2026-8836-critical-embedded-rce
  checkedAt: '2026-09-24T07:53:23.059Z'
exploitAvailable: true
---

## Overview

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameters results in stack-based buffer overflow. The attack may be initiated remotely. The patch is named 0c957ec03054eb6c8205e9c9d1d05d90ada3898c. It is suggested to install a patch to address this issue. Two separate issue reports were submitted to the project. Their processing was merged as a duplicate.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
