Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2025-14858

PUBLISHED 07.04.2026

CNA: SWI

Semtech LR11xx Encrypted Firmware Disclosure

Обновлено: 07.04.2026
The Semtech LR11xx LoRa transceivers running early versions of firmware contains an information disclosure vulnerability in its firmware validation functionality. When a host issues a firmware validity check command via the SPI interface, the device decrypts the provided encrypted firmware package block-by-block to validate its integrity. However, the last decrypted firmware block remains uncleared in memory after the validation process completes. An attacker with access to the SPI interface can subsequently issue memory read commands to retrieve the decrypted firmware contents from this residual memory, effectively bypassing the firmware encryption protection mechanism. The attack requires physical access to the device's SPI interface.

CWE

Идентификатор Описание
CWE-226 The product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or "zeroize" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities.

CVSS

Оценка Severity Версия Базовый вектор
5.1 MEDIUM 4.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:N/R:A/V:C/RE:M

Доп. Информация

Product Status

LR1110
Product: LR1110
Vendor: Semtech
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до TRX FW 0x0402 affected
LR1120
Product: LR1120
Vendor: Semtech
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до TRX FW 0x0202 affected
LR1121
Product: LR1121
Vendor: Semtech
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до TRX FW 0x0104 affected
 

Ссылки

CISA ADP Vulnrichment

Обновлено: 07.04.2026
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
none no total 2.0.3 07.04.2026

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.