{"id":"CVE-2025-14859","title":"The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware","summary":"The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware. However, the implementation uses a non-standard cryptographic hashing algorithm that is vulnerable to second prei…","severity":"none","cwe":["CWE-327"],"published":"2026-04-07","updated":"2026-07-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-14859","references":[{"url":"https://www.semtech.com/company/security/security-bulletins/sem-psa-2026-001","label":"security@sierrawireless.com"}],"tags":["nvd"],"epss":0.0011,"epssPercentile":0.01419,"ingestedAt":"2026-07-25T23:05:57.794Z","slug":"CVE-2025-14859","body":"## Overview\n\nThe Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware. However, the implementation uses a non-standard cryptographic hashing algorithm that is vulnerable to second preimage attacks. An attacker with physical access to the device can exploit this weakness to generate a malicious firmware image with a hash collision, bypassing the secure boot verification mechanism and installing arbitrary unauthorized firmware on the device.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}