PT-2026-46901 · Morse Micro · Halowlink 2
Published
2026-06-05
·
Updated
2026-06-05
·
CVE-2026-7763
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon frame containing a malformed Traffic Indication Map (TIM) Information Element. The function morse page slicing process tim element() in page slicing.c derives the TIM bitmap length directly from a received IE field without validating it against the fixed-size destination buffer before passing it to memset and memcpy operations, allowing up to 252 bytes of attacker-controlled data to be written beyond the buffer boundary. Because beacons are broadcast frames processed during passive scanning, no authentication, association, or user interaction is required.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Halowlink 2