LoRa Transceiver Firmware Vulnerability in Semtech Devices
CVE-2025-14859
7HIGH
What is CVE-2025-14859?
The Semtech LR11xx LoRa transceivers experience a significant firmware vulnerability due to their use of a non-standard cryptographic hashing algorithm for secure boot functionality. This vulnerability permits a malicious actor with physical access to generate a counterfeit firmware image that matches an existing hash, effectively bypassing the secure boot verification mechanism. As a result, unauthorized firmware can be installed on affected devices, posing serious security risks.
Affected Version(s)
LR1110 0
LR1120 0
LR1121 0
