An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware where the memory…
SWI·CWE-123·Published 2026-04-07
An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware where the memory write command accessible via the physical SPI interface fails to enforce write protection on the program call stack. An attacker with physical access to the SPI interface can overwrite stack memory to hijack program control flow and achieve limited arbitrary code execution. However, the impact is limited to the active attack session: the device's secure boot mechanism prevents persistent firmware modification, the crypto engine isolates cryptographic keys from direct firmware access, and all modifications are lost upon device reboot or loss of physical access.
An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware where the memory write command accessible via the physical SPI interface fails to enforce write protection on the program call stack. An attacker with physical access to the SPI interface can overwrite stack memory to hijack program control flow and achieve limited arbitrary code execution. However, the impact is limited to the active attack session: the device's secure boot mechanism prevents persistent firmware modification, the crypto engine isolates cryptographic keys from direct firmware access, and all modifications are lost upon device reboot or loss of physical access.
Una vulnerabilidad de control de acceso inadecuado existe en los transceptores Semtech LoRa LR11xxx que ejecutan versiones tempranas de firmware donde el comando de escritura de memoria accesible a través de la interfaz SPI física no logra aplicar la protección contra escritura en la pila de llamadas del programa. Un atacante con acceso físico a la interfaz SPI puede sobrescribir la memoria de la pila para secuestrar el flujo de control del programa y lograr una ejecución de código arbitrario limitada. Sin embargo, el impacto se limita a la sesión de ataque activa: el mecanismo de arranque seguro del dispositivo evita la modificación persistente del firmware, el motor criptográfico aísla las claves criptográficas del acceso directo al firmware, y todas las modificaciones se pierden al reiniciar el dispositivo o al perder el acceso físico.
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 4.0 | Primary | cve.org | 5.4 | — | — | CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/AU:N/R:A/V:D/RE:M |
| 4.0 | Secondary | NVD | 5.4 | — | — |
| CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:X |