PT-2026-77289 · Sierra Wireless · Hl7800 Cellular Modem Driver
CVE-2026-12520
·
Published
2026-08-18
·
Updated
2026-08-18
CVSS v3.1
6.4
Medium
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Sierra Wireless HL7800 cellular modem driver versions prior to 4.4.0
Description
The driver contains multiple issues when parsing AT responses. Approximately twenty handlers use the
net buf linearize() function to copy data into a 128-byte stack buffer. Because net buf linearize() can return a count equal to the destination length, a field that exactly fills the buffer causes a single-byte out-of-bounds write of a NUL terminator into adjacent stack memory. Additionally, the on cmd atcmdinfo rssi() handler for +KCELLMEAS cell-measurement incorrectly uses the wire length len as the destination size, allowing response lines longer than 128 bytes to overflow the stack buffer with attacker-controlled content. This data originates from the cellular modem over UART and can be influenced by a rogue base station, a compromised modem baseband, or a remote peer. Since these handlers execute in the driver's RX thread in kernel context, this can lead to a kernel-side crash or arbitrary code execution.Recommendations
Update the Sierra Wireless HL7800 cellular modem driver to a version later than 4.4.0.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hl7800 Cellular Modem Driver