๐Ÿ” CVE Alert

CVE-2025-14858

UNKNOWN 0.0

Semtech LR11xx Encrypted Firmware Disclosure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Semtech LR11xx LoRa transceivers running early versions of firmware contains an information disclosure vulnerability in its firmware validation functionality. When a host issues a firmware validity check command via the SPI interface, the device decrypts the provided encrypted firmware package block-by-block to validate its integrity. However, the last decrypted firmware block remains uncleared in memory after the validation process completes. An attacker with access to the SPI interface can subsequently issue memory read commands to retrieve the decrypted firmware contents from this residual memory, effectively bypassing the firmware encryption protection mechanism. The attack requires physical access to the device's SPI interface.

CWE CWE-226
Vendor semtech
Product lr1110
Published Apr 7, 2026
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for semtech lr1110

Be the first to know when new unknown vulnerabilities affecting semtech lr1110 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Semtech / LR1110
0 < TRX FW 0x0402
Semtech / LR1120
0 < TRX FW 0x0202
Semtech / LR1121
0 < TRX FW 0x0104

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
semtech.com: https://www.semtech.com/company/security/security-bulletins/sem-psa-2026-001

Credits

Egor (radioegor146) Koleda, https://github.com/radioegor146