---
id: CVE-2025-14859
title: >-
  The Semtech LR11xx LoRa transceivers implement secure boot functionality using
  digital signatures to authenticate firmware
summary: >-
  The Semtech LR11xx LoRa transceivers implement secure boot functionality using
  digital signatures to authenticate firmware. However, the implementation uses
  a non-standard cryptographic hashing algorithm that is vulnerable to second
  prei…
severity: none
cwe:
  - CWE-327
published: '2026-04-07'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14859'
references:
  - url: >-
      https://www.semtech.com/company/security/security-bulletins/sem-psa-2026-001
    label: security@sierrawireless.com
tags:
  - nvd
epss: 0.0011
epssPercentile: 0.01143
ingestedAt: '2026-07-25T23:05:57.794Z'
---

## Overview

The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware. However, the implementation uses a non-standard cryptographic hashing algorithm that is vulnerable to second preimage attacks. An attacker with physical access to the device can exploit this weakness to generate a malicious firmware image with a hash collision, bypassing the secure boot verification mechanism and installing arbitrary unauthorized firmware on the device.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
