Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-13480— Out-of-bounds read in LoRaWAN fragmented data block transport (FUOTA) downlink handler

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述的中文翻译: LoRaWAN TS004 分块数据块传输处理器 (位于 )在解析下行命令字节时,未在校验每次访问前是否还有足够的负载字节。该循环唯一的边界条件是 ;在消耗掉 1 字节的命令 ID 后,处理器将 强制转换为 10 字节的结构体 ;对于 命令,则将 传递给分块解码器,该解码器会精确读取 个字节——在这两种情况下,均没有对剩余长度进行检查。 分块大小是由攻击者在之前的 命令中指定的( ,上限为 ,默认值为 232)。 是 LoRaMAC 节点 MAC 层中 255 字节静态 缓冲区的别名,

CVSS 3.1 · Low

Possible ATT&CK Techniques 2 AI

T1082 · System Information Discovery T1015

Affected Version Matrix 1

VendorProduct Version RangeStatus
zephyrproject zephyr 3.7.0< 4.4.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-13480

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Out-of-bounds read in LoRaWAN fragmented data block transport (FUOTA) downlink handler
Source: CVE Program / CVE List V5
Vulnerability Description
The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package_callback() in subsys/lorawan/services/frag_transport.c parses downlink command bytes without validating that enough payload bytes remain before each access. The loop's only bound is rx_pos < len; after consuming the one-byte command id the handler cast rx_buf + rx_pos to a 10-byte struct frag_transport_setup_req, and for a DATA_FRAGMENT command passed &rx_buf[rx_pos] to the fragment decoder, which reads exactly ctx.frag_size bytes — with no remaining-length check in either case. The fragment size is attacker-chosen in a preceding FRAG_SESSION_SETUP command (ctx.frag_size = req->frag_size, capped at CONFIG_LORAWAN_FRAG_TRANSPORT_MAX_FRAG_SIZE, default 232). rx_buf aliases the 255-byte static MacCtx.RxPayload buffer in the loramac-node MAC layer, while len is the actual decrypted payload length. By padding a downlink with mismatched-index DATA_FRAGMENT filler commands (each advancing rx_pos by three bytes without producing an answer) and appending one matching-index fragment near the end of the payload, an attacker can make the decoder read up to roughly frag_size bytes past the end of RxPayload, copying adjacent static memory into the decoder buffers and the FUOTA flash image. The handler runs only on downlinks that have already passed the LoRaWAN frame MIC and FRMPayload decryption, so the defect is reachable only by a party holding the device's session keys (the FUOTA server or an attacker who has compromised those keys). The out-of-bounds bytes are never returned to the sender — the only uplink emitted is a status answer carrying fragment counts — so there is no direct disclosure channel, and on typical flat-memory LoRaWAN MCUs the over-read stays within mapped memory, making a crash unlikely. The impact is therefore a bounded out-of-bounds read with limited confidentiality consequence and no write or control-flow primitive. The fix adds remaining-length guards before each access.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 3.7.0 ~ 4.4.2 -

II. Public POCs for CVE-2026-13480

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-13480

登录查看更多情报信息。

Patches & Fixes for CVE-2026-13480 (1)

Vendor Advisories for CVE-2026-13480 (1)

Same Patch Batch · zephyrproject · 2026-08-26 · 3 CVEs total

CVE-2026-13481 5.4 MEDIUM Out-of-bounds read in PTP management TLV TIME parsing in Zephyr net PTP
CVE-2026-13479 3.1 LOW Out-of-bounds read in LoRaWAN clock-sync AppTimeAns downlink handler

IV. Related Vulnerabilities

V. Comments for CVE-2026-13480

No comments yet


Leave a comment