CVE-2020-22283: Lwip Project Lwip

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

A buffer overflow vulnerability in the icmp6_send_response_with_addrs_and_netif() function of Free Software Foundation lwIP version git head allows attackers to access sensitive information via a crafted ICMPv6 packet.

Affected products

Published 2021-07-22. Last modified 2026-06-17.