VYPR
Vendor

Semtech

Products
4
CVEs
6
Across products
6
Status
Private

Products

4

Recent CVEs

6
  • CVE-2025-14859HigApr 7, 2026
    risk 0.46cvss epss 0.00

    The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware. However, the implementation uses a non-standard cryptographic hashing algorithm that is vulnerable to second preimage attacks. An attacker with physical…

  • CVE-2025-14857MedApr 7, 2026
    risk 0.35cvss epss 0.00

    An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware where the memory write command accessible via the physical SPI interface fails to enforce write protection on the program call stack. An attacker with physical…

  • CVE-2025-14858MedApr 7, 2026
    risk 0.33cvss epss 0.00

    The Semtech LR11xx LoRa transceivers running early versions of firmware contains an information disclosure vulnerability in its firmware validation functionality. When a host issues a firmware validity check command via the SPI interface, the device decrypts the provided…

  • CVE-2020-4060MedJun 22, 2020
    risk 0.27cvss 4.1epss 0.01

    In LoRa Basics Station before 2.0.4, there is a Use After Free vulnerability that leads to memory corruption. This bug is triggered on 32-bit machines when the CUPS server responds with a message (https://doc.sm.tc/station/cupsproto.html#http-post-response) where the signature…

  • CVE-2022-39274HigOct 6, 2022
    risk 0.00cvss 7.5epss 0.02

    LoRaMac-node is a reference implementation and documentation of a LoRa network node. Versions of LoRaMac-node prior to 4.7.0 are vulnerable to a buffer overflow. Improper size validation of the incoming radio frames can lead to an 65280-byte out-of-bounds write. The function…

  • CVE-2020-11068MedJun 23, 2020
    risk 0.00cvss 5.0epss 0.01

    In LoRaMac-node before 4.4.4, a reception buffer overflow can happen due to the received buffer size not being checked. This has been fixed in 4.4.4.