PT-2026-30996 · Semtech · Lr11Xx Lora Transceivers

Published

2026-04-07

·

Updated

2026-04-08

·

CVE-2025-14859

CVSS v4.0

7.0

High

VectorAV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:I/V:C/RE:M/U:X
Name of the Vulnerable Software and Affected Versions Semtech LR11xx LoRa transceivers (affected versions not specified)
Description The Semtech LR11xx LoRa transceivers utilize secure boot with digital signatures for firmware authentication. The implementation employs a non-standard cryptographic hashing algorithm susceptible to second preimage attacks. An attacker with physical access can exploit this to create a malicious firmware image with a hash collision, circumventing secure boot verification and enabling the installation of unauthorized firmware.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14859

Affected Products

Lr11Xx Lora Transceivers