CVE-2025-14857
An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware where the memory write command accessible via the physical SPI interface fails to enforce write protection on the program call stack. An attacker with physical access to the SPI interface can overwrite stack memory to hijack program control flow and achieve limited arbitrary code execution. However, the impact is limited to the active attack session: the device's secure boot mechanism prevents persistent firmware modification, the crypto engine isolates cryptographic keys from direct firmware access, and all modifications are lost upon device reboot or loss of physical access.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:X
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.24%
- Percentil entre todas las CVEs puntuadas: 14
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-123
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-14857",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-14857",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-04-07T20:31:21.612362Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "security@sierrawireless.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "AUTOMATIC",
"baseScore": 5.4,
"Automatable": "NO",
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"valueDensity": "DIFFUSE",
"vectorString": "CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "LOW",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "LOW",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "MODERATE",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "security@sierrawireless.com",
"affectedData": [
{
"vendor": "Semtech",
"modules": [
"firmware"
],
"product": "LR1110",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "TRX FW 0x0402",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Semtech",
"product": "LR1120",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "TRX FW 0x0202",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Semtech",
"product": "LR1121",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "TRX FW 0x0104",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-04-07T20:16:21.253",
"references": [
{
"url": "https://www.semtech.com/company/security/security-bulletins/sem-psa-2026-001",
"source": "security@sierrawireless.com"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "security@sierrawireless.com",
"description": [
{
"lang": "en",
"value": "CWE-123"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware where the memory write command accessible via the physical SPI interface fails to enforce write protection on the program call stack. An attacker with physical access to the SPI interface can overwrite stack memory to hijack program control flow and achieve limited arbitrary code execution. However, the impact is limited to the active attack session: the device's secure boot mechanism prevents persistent firmware modification, the crypto engine isolates cryptographic keys from direct firmware access, and all modifications are lost upon device reboot or loss of physical access."
},
{
"lang": "es",
"value": "Una vulnerabilidad de control de acceso inadecuado existe en los transceptores Semtech LoRa LR11xxx que ejecutan versiones tempranas de firmware donde el comando de escritura de memoria accesible a través de la interfaz SPI física no logra aplicar la protección contra escritura en la pila de llamadas del programa. Un atacante con acceso físico a la interfaz SPI puede sobrescribir la memoria de la pila para secuestrar el flujo de control del programa y lograr una ejecución de código arbitrario limitada. Sin embargo, el impacto se limita a la sesión de ataque activa: el mecanismo de arranque seguro del dispositivo evita la modificación persistente del firmware, el motor criptográfico aísla las claves criptográficas del acceso directo al firmware, y todas las modificaciones se pierden al reiniciar el dispositivo o al perder el acceso físico."
}
],
"lastModified": "2026-07-24T23:10:00.563",
"sourceIdentifier": "security@sierrawireless.com"
}