« Volver al listado

CVE-2026-7763

Estado: Pendiente de análisisCrítica (9.8)—

A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon frame containing a malformed Traffic Indication Map (TIM) Information Element.

Leer descripción completaMostrar menos

The function morse_page_slicing_process_tim_element() in page_slicing.c derives the TIM bitmap length directly from a received IE field without validating it against the fixed-size destination buffer before passing it to memset and memcpy operations, allowing up to 252 bytes of attacker-controlled data to be written beyond the buffer boundary. Because beacons are broadcast frames processed during passive scanning, no authentication, association, or user interaction is required.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de desbordamiento de búfer en controlador Wi-Fi explotable remotamente sin autenticación (AV:N, PR:N, UI:N). Beacon frames malformados causan pánico del kernel (DoS) o potencial ejecución de código arbitrario en contexto de kernel.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-7763",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-7763",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-05T20:20:06.506327Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "4ac701fe-44e9-4bcd-9585-dd6449257611",
      "affectedData": [
        {
          "vendor": "Morse Micro",
          "product": "HaLowLink 2",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.11.13",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-06-05T02:17:14.640",
  "references": [
    {
      "url": "https://www.morsemicro.com/security-advisories/MM-SA-2026-001",
      "source": "4ac701fe-44e9-4bcd-9585-dd6449257611"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon frame containing a malformed Traffic Indication Map (TIM) Information Element. The function morse_page_slicing_process_tim_element() in page_slicing.c derives the TIM bitmap length directly from a received IE field without validating it against the fixed-size destination buffer before passing it to memset and memcpy operations, allowing up to 252 bytes of attacker-controlled data to be written beyond the buffer boundary. Because beacons are broadcast frames processed during passive scanning, no authentication, association, or user interaction is required."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de desbordamiento de búfer basado en montículo en el controlador de kernel Wi-Fi HaLow morse.ko en versiones de software Morse Micro HaLowLink 2 anteriores a la 2.11.13 permite a un atacante no autenticado dentro del alcance de radio causar una denegación de servicio (pánico del kernel) o potencialmente lograr ejecución remota de código a través de una trama de baliza 802.11ah manipulada que contiene un Elemento de Información de Mapa de Indicación de Tráfico (TIM) malformado. La función morse_page_slicing_process_tim_element() en page_slicing.c deriva la longitud del mapa de bits TIM directamente de un campo IE recibido sin validarlo contra el búfer de destino de tamaño fijo antes de pasarlo a operaciones memset y memcpy, permitiendo hasta 252 bytes de datos controlados por el atacante ser escritos más allá del límite del búfer. Debido a que las balizas son tramas de difusión procesadas durante el escaneo pasivo, no se requiere autenticación, asociación o interacción del usuario."
    }
  ],
  "lastModified": "2026-07-23T07:10:00.113",
  "sourceIdentifier": "4ac701fe-44e9-4bcd-9585-dd6449257611"
}