← All Advisories

Semtech LR11xx LoRa secure boot second-preimage weakness enables unauthorized firmware installation via physical access

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2025-14859

Key Details

CVECVE-2025-14859
CVSS Score / Version7.0 (High) / CVSS v4.0
Updated2026-07-24
Classified asCWE-327 (Use of a Broken or Risky Cryptographic Algorithm)

What to Know

The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware. However, the implementation uses a non-standard cryptographic hashing algorithm that is vulnerable to second preimage attacks. An attacker with physical access to the device can exploit this weakness to generate a malicious firmware image with a hash collision, bypassing the secure boot verification mechanism and installing arbitrary unauthorized firmware on the device. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-14859
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-14859