Lwip · Lwip · CVE-2026-8836
**Name of the Vulnerable Software and Affected Versions**
lwIP versions prior to 2.2.2
**Description**
A stack-based buffer overflow exists in the snmpv3 USM Handler component. A remote attacker can trigger this issue by manipulating the `msgAuthenticationParameters` argument within the `snmp parse inbound frame()` function located in the `src/apps/snmp/snmp msg.c` file.
**Recommendations**
Install patch 0c957ec03054eb6c8205e9c9d1d05d90ada3898c.
As a temporary workaround, restrict access to the snmpv3 USM Handler component to minimize the risk of exploitation.