{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-14859","assignerOrgId":"747bec18-acd0-4d99-a5c8-5e366c66ab7e","state":"PUBLISHED","assignerShortName":"SWI","dateReserved":"2025-12-18T00:09:40.606Z","datePublished":"2026-04-07T19:58:41.379Z","dateUpdated":"2026-04-07T20:42:41.142Z"},"containers":{"cna":{"providerMetadata":{"orgId":"747bec18-acd0-4d99-a5c8-5e366c66ab7e","shortName":"SWI","dateUpdated":"2026-04-07T19:58:41.379Z"},"title":"Semtech LR11xx Secure Boot Bypass","datePublic":"2026-04-06T18:07:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-327","description":"CWE-327 Use of a Broken or Risky Cryptographic Algorithm","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-68","descriptions":[{"lang":"en","value":"CAPEC-68 Subvert Code-signing"}]}],"affected":[{"vendor":"Semtech","product":"LR1110","modules":["firmware"],"versions":[{"status":"affected","version":"0","lessThan":"BL2 FW 0x1001","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"Semtech","product":"LR1120","versions":[{"status":"affected","version":"0","lessThan":"BL2 FW 0x2001","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"Semtech","product":"LR1121","versions":[{"status":"affected","version":"0","lessThan":"BL2 FW 0x2101","versionType":"custom"}],"defaultStatus":"unaffected"}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:semtech:lr1110:*:*:*:*:*:*:*:*","versionEndExcluding":"bl2_fw_0x1001","versionStartIncluding":"0","vulnerable":true}],"negate":false,"operator":"OR"},{"cpeMatch":[{"criteria":"cpe:2.3:a:semtech:lr1120:*:*:*:*:*:*:*:*","versionEndExcluding":"bl2_fw_0x2001","versionStartIncluding":"0","vulnerable":true}],"negate":false,"operator":"OR"},{"cpeMatch":[{"criteria":"cpe:2.3:a:semtech:lr1121:*:*:*:*:*:*:*:*","versionEndExcluding":"bl2_fw_0x2101","versionStartIncluding":"0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"OR"}],"descriptions":[{"lang":"en","value":"The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware. However, the implementation uses a non-standard cryptographic hashing algorithm that is vulnerable to second preimage attacks. An attacker with physical access to the device can exploit this weakness to generate a malicious firmware image with a hash collision, bypassing the secure boot verification mechanism and installing arbitrary unauthorized firmware on the device.","supportingMedia":[{"type":"text/html","base64":false,"value":"The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware. However, the implementation uses a non-standard cryptographic hashing algorithm that is vulnerable to second preimage attacks. An attacker with physical access to the device can exploit this weakness to generate a malicious firmware image with a hash collision, bypassing the secure boot verification mechanism and installing arbitrary unauthorized firmware on the device.\n\n<br>"}]}],"references":[{"url":"https://www.semtech.com/company/security/security-bulletins/sem-psa-2026-001"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"PHYSICAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"LOW","vulnAvailabilityImpact":"HIGH","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NO","Recovery":"IRRECOVERABLE","valueDensity":"CONCENTRATED","vulnerabilityResponseEffort":"MODERATE","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"HIGH","baseScore":7,"vectorString":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/AU:N/R:I/V:C/RE:M"}}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 0.5.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2025-14859","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2026-04-07T20:31:39.343091Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-04-07T20:42:41.142Z"}}]}}