216.73.217.15

CVE-2026-7763

· Published 05/06/2026 02:17 · Modified 05/06/2026 21:16

Labels: CVE-2026-7763 2026-06-054ac701fe-44e9-4bcd-9585-dd6449257611CVE-2026-7763

Essential information

Published
05/06/2026 02:17
Modified
05/06/2026 21:16
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon frame containing a malformed Traffic Indication Map (TIM) Information Element. The function morse_page_slicing_process_tim_element() in page_slicing.c derives the TIM bitmap length directly from a received IE field without validating it against the fixed-size destination buffer before passing it to memset and memcpy operations, allowing up to 252 bytes of attacker-controlled data to be written beyond the buffer boundary. Because beacons are broadcast frames processed during passive scanning, no authentication, association, or user interaction is required.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
4ac701fe-44e9-4bcd-9585-dd6449257611
NVD
View on NVD

Affected products (CPE)

ProductCPE
morse / morse halowlink cpe:2.3:a:morse:morse_halowlink:<2.11.13:*:*:*:*:*:*:*

References