๐Ÿ” CVE Alert

CVE-2025-14859

UNKNOWN 0.0

Semtech LR11xx Secure Boot Bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware. However, the implementation uses a non-standard cryptographic hashing algorithm that is vulnerable to second preimage attacks. An attacker with physical access to the device can exploit this weakness to generate a malicious firmware image with a hash collision, bypassing the secure boot verification mechanism and installing arbitrary unauthorized firmware on the device.

CWE CWE-327
Vendor semtech
Product lr1110
Published Apr 7, 2026
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for semtech lr1110

Be the first to know when new unknown vulnerabilities affecting semtech lr1110 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Semtech / LR1110
0 < BL2 FW 0x1001
Semtech / LR1120
0 < BL2 FW 0x2001
Semtech / LR1121
0 < BL2 FW 0x2101

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
semtech.com: https://www.semtech.com/company/security/security-bulletins/sem-psa-2026-001