PT-2026-46901 · Morse Micro · Halowlink 2
CVE-2026-7763
·
Published
2026-06-05
·
Updated
2026-06-05
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Morse Micro HaLowLink 2 versions prior to 2.11.13
Description
A heap-based buffer overflow exists in the
morse.ko HaLow Wi-Fi kernel driver. An unauthenticated attacker within radio range can cause a Denial of Service resulting in a kernel panic or potentially achieve Remote Code Execution by sending a crafted 802.11ah beacon frame containing a malformed Traffic Indication Map (TIM) Information Element. The function morse page slicing process tim element() in page slicing.c derives the TIM bitmap length from a received IE field without validating it against the fixed-size destination buffer before performing memset and memcpy operations. This allows up to 252 bytes of attacker-controlled data to be written beyond the buffer boundary. Since beacons are broadcast frames processed during passive scanning, no authentication, association, or user interaction is required.Recommendations
Update to version 2.11.13 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Halowlink 2