Stack Buffer Overflow in WNC-M14A2A LTE-M Modem Driver by Zephyr Project
CVE-2026-12519

5MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-12519?

The WNC-M14A2A LTE-M modem driver has a vulnerability that arises from the mishandling of unsolicited %NOTIFYEV: events. This issue occurs when the response line is incorrectly processed into a fixed-size stack buffer. Due to improperly bounded scanning loops, an attacker can exploit this flaw through a malicious or compromised cellular base station, leading to out-of-bounds memory access. This could cause sensitive information to be disclosed and may result in stack corruption, potentially crashing the modem's RX thread without requiring application-level interaction.

Affected Version(s)

zephyr 1.13.0 < 4.4.2

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.