SEM-PSA-2026-001: LR11xx Security Advisory

Apr 7, 2026 - Author: Semtech

Semtech was made aware of two security vulnerabilities (CVE-2025-14857 and CVE-2025-14858) and internally discovered a third vulnerability (CVE-2025-14859) that affects certain Semtech LoRa transceivers and modems.  These vulnerabilities could allow unauthenticated firmware to be loaded and executed on affected devices. These vulnerabilities require physical access to exploit and cannot be leveraged remotely.

Download Bulletin: SEM-PSA-2026-001