The lwip Project develops a compact TCP/IP stack implementation widely embedded in embedded systems, IoT devices, and resource-constrained network applications, where it serves as a lightweight alternative to full operating-system network stacks. The vulnerability profile centers on memory-safety and data-validation issues inherent to C-based network parsing, with recurring exposure in classic buffer overflows and insufficient verification of data authenticity that are characteristic of protocol-handling code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lwip Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-22284HIGH A buffer overflow vulnerability in the zepif_linkoutput() function of Free Software Foundation lwIP git head version and version 2.1.2 allows attackers to access sensitive informat | Jul 22, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-22283HIGH A buffer overflow vulnerability in the icmp6_send_response_with_addrs_and_netif() function of Free Software Foundation lwIP version git head allows attackers to access sensitive in | Jul 22, 2021 | 7.5 | 24 | NO | NO |
CVE-2014-4883MEDIUM resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which | Nov 28, 2014 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lwip Project.
Media articles that mention a CVE ID that affects a product developed by Lwip Project — matched by CVE ID, not by vendor name.