Stack Buffer Overflow in WNC-M14A2A LTE-M Modem Driver by Zephyr Project
CVE-2026-12519
5MEDIUM
What is CVE-2026-12519?
The WNC-M14A2A LTE-M modem driver has a vulnerability that arises from the mishandling of unsolicited %NOTIFYEV: events. This issue occurs when the response line is incorrectly processed into a fixed-size stack buffer. Due to improperly bounded scanning loops, an attacker can exploit this flaw through a malicious or compromised cellular base station, leading to out-of-bounds memory access. This could cause sensitive information to be disclosed and may result in stack corruption, potentially crashing the modem's RX thread without requiring application-level interaction.
Affected Version(s)
zephyr 1.13.0 < 4.4.2
