Executive brief
A security vulnerability exists in the Morse Micro HaLow Wi-Fi driver, which is used to provide long-range wireless connectivity for IoT devices. An attacker within radio range can send a specially crafted Wi-Fi signal to crash the device or potentially take full control of it. This attack requires no user interaction and can be performed even if the attacker is not logged into the network, potentially leading to service outages or unauthorized access to device data.
Technical details
A heap-based buffer overflow exists in the morse.ko HaLow Wi-Fi kernel driver within the morse_page_slicing_process_tim_element() function in page_slicing.c. The vulnerability is caused by the driver deriving the Traffic Indication Map (TIM) bitmap length directly from a received Information Element (IE) field without validating it against the fixed-size destination buffer. This allows an attacker to trigger memset and memcpy operations that write up to 252 bytes of controlled data beyond the buffer boundaries. The attack is delivered via a crafted 802.11ah beacon frame and is processed during passive scanning, meaning no authentication or association is required. This can result in a Denial of Service (kernel panic) or Remote Code Execution (RCE). The issue is resolved in HaLowLink 2 software version 2.11.13.
Affected products
- Morse Micro HaLowLink 2 software prior to 2.11.13
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory