Junglewise Threat Intelligence

CVE-2025-14858: Semtech LR11xx information disclosure in firmware validation

CVE-2025-14858 · Severity: info · CVSS 5.1 · Published 2026-04-07

Technologies: Semtech LR1120, Semtech LR1121, Semtech LR1110. Vendors: Semtech.

Executive brief

Semtech LR11xx transceivers, which are chips used for long-range wireless communication in IoT devices, contain a flaw that could allow an attacker to steal sensitive firmware data. By physically accessing the device's hardware interface, an attacker can recover pieces of decrypted software that were supposed to remain protected. This could lead to the theft of intellectual property or help an attacker find further ways to compromise the device.

Technical details

An information disclosure vulnerability (CWE-226) exists in the firmware validation functionality of Semtech LR11xx transceivers. When the device performs a firmware validity check via the Serial Peripheral Interface (SPI), it decrypts the firmware block-by-block; however, the final decrypted block is not cleared from memory upon completion. An attacker with physical access to the SPI interface can issue memory read commands to retrieve these residual decrypted contents. This allows for the gradual extraction of firmware data, effectively bypassing the device's firmware encryption protections. The issue is addressed in firmware versions TRX FW 0x0402 (LR1110), 0x0202 (LR1120), and 0x0104 (LR1121).

Affected products

  • Semtech LR1110 TRX FW < 0x0402
  • Semtech LR1120 TRX FW < 0x0202
  • Semtech LR1121 TRX FW < 0x0104

Timeline

  • 2026-04-07: disclosed: Initial disclosure by Semtech
  • 2026-04-07: advisory: NVD publication date

References

Related threats