The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware. However, the implementation uses a non-standard cryptographic hashing algorithm that is vulnerable to second preimage attacks. An attacker with physical access to the device can exploit this weakness to generate a malicious firmware image with a hash collision, bypassing the secure b [truncated]
CVE-2025-14858 is an information disclosure vulnerability in Semtech LR11xx LoRa transceivers running early firmware versions. The vulnerability occurs in the firmware validation functionality, where the device decrypts provided encrypted firmware packages block-by-block to validate integrity. However, the last decrypted firmware block remains uncleared in memory after validation completes. An attacker wi [truncated]
An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware. The memory write command accessible via the physical SPI interface fails to enforce write protection on the program call stack. This allows an attacker with physical access to the SPI interface to overwrite stack memory, hijack program control flow, and achieve limited arbitrary code ex [truncated]