PT-2026-77289 · Sierra Wireless · Hl7800 Cellular Modem Driver

CVE-2026-12520

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

6.4

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Sierra Wireless HL7800 cellular modem driver versions prior to 4.4.0
Description The driver contains multiple issues when parsing AT responses. Approximately twenty handlers use the net buf linearize() function to copy data into a 128-byte stack buffer. Because net buf linearize() can return a count equal to the destination length, a field that exactly fills the buffer causes a single-byte out-of-bounds write of a NUL terminator into adjacent stack memory. Additionally, the on cmd atcmdinfo rssi() handler for +KCELLMEAS cell-measurement incorrectly uses the wire length len as the destination size, allowing response lines longer than 128 bytes to overflow the stack buffer with attacker-controlled content. This data originates from the cellular modem over UART and can be influenced by a rogue base station, a compromised modem baseband, or a remote peer. Since these handlers execute in the driver's RX thread in kernel context, this can lead to a kernel-side crash or arbitrary code execution.
Recommendations Update the Sierra Wireless HL7800 cellular modem driver to a version later than 4.4.0.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12520
GHSA-9XC4-J5X8-V6JX

Affected Products

Hl7800 Cellular Modem Driver