Junglewise Threat Intelligence

CVE-2025-14859: Semtech LR11xx secure boot bypass via cryptographic hash collision

CVE-2025-14859 · Severity: info · CVSS 7 · Published 2026-04-07

Technologies: Semtech LR1120, Semtech LR1121, Semtech LR1110. Vendors: Semtech.

Executive brief

Semtech LR11xx transceivers, which are chips used for long-range wireless communication in IoT devices, contain a flaw in how they verify software updates. An attacker with physical access to the hardware could bypass security checks to install and run unauthorized software. This could lead to a total loss of device integrity, allowing the attacker to control the device's operations or steal sensitive data.

Technical details

The Semtech LR11xx LoRa transceivers (LR1110, LR1120, LR1121) utilize a non-standard cryptographic hashing algorithm within their secure boot process. This algorithm is vulnerable to second preimage attacks, allowing an attacker to create a malicious firmware image that produces the same hash as a legitimate, signed image. Exploitation requires physical access to the device to load the malicious firmware. Successful exploitation bypasses digital signature verification, enabling the execution of arbitrary unauthorized code. The issue is addressed in updated bootloader (BL2) firmware versions.

Affected products

  • Semtech LR1110 Before BL2 FW 0x1001
  • Semtech LR1120 Before BL2 FW 0x2001
  • Semtech LR1121 Before BL2 FW 0x2101

Timeline

  • 2026-04-07: disclosed
  • 2026-04-07: advisory

References

Related threats