Semtech develops wireless connectivity components and software, with observed vulnerabilities centered on its LoRa MAC implementations and the LoRa Basics Station gateway software used in long-range IoT deployments. The recurring weakness classes—classic buffer overflows, off-by-one errors, and use-after-free conditions—reflect memory-safety gaps typical of embedded networking firmware and C-based protocol stacks. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Semtech Corporation over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39274CRITICAL LoRaMac-node is a reference implementation and documentation of a LoRa network node. Versions of LoRaMac-node prior to 4.7.0 are vulnerable to a buffer overflow. Improper size vali | Oct 6, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-11068HIGH In LoRaMac-node before 4.4.4, a reception buffer overflow can happen due to the received buffer size not being checked. This has been fixed in 4.4.4. | Jun 23, 2020 | 8.8 | 28 | NO | NO |
CVE-2020-4060MEDIUM In LoRa Basics Station before 2.0.4, there is a Use After Free vulnerability that leads to memory corruption. This bug is triggered on 32-bit machines when the CUPS server responds | Jun 22, 2020 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Semtech Corporation.
Media articles that mention a CVE ID that affects a product developed by Semtech Corporation — matched by CVE ID, not by vendor name.