CVE-2025-14859 affects Semtech LR11xx LoRa transceivers and involves a weakness in their secure boot implementation. The vulnerability exploits a non-standard cryptographic hashing algorithm used to authenticate firmware, which is susceptible to second preimage attacks. This allows an attacker with physical device access to generate malicious firmware with hash collisions, thereby bypassing secure boot verification and installing unauthorized code. The attack requires physical access to the device, limiting its practical threat scope to scenarios involving insider threats or device theft. While the specific CVSS vector is not publicly available, the attack complexity is relatively low once physical access is obtained. The potential impact is severe, as successful exploitation grants complete control over device firmware with no authentication barriers post-compromise. There is no evidence of active exploitation in the wild, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog. The EPSS score of 0.0001 indicates minimal real-world exploitation activity. Community attention appears limited, though the moderate FAUCET risk score of 37.0 suggests organizations deploying Semtech LR11xx devices should evaluate their physical security controls and consider firmware update deployment once patches become available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Semtech | LR1110 | >= 0, < BL2 FW 0x1001CNA affecteddefault unaffected | |
| Semtech | LR1120 | >= 0, < BL2 FW 0x2001CNA affecteddefault unaffected | |
| Semtech | LR1121 | >= 0, < BL2 FW 0x2101CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:I/V:C/RE:M/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.