CVE-2026-7763

Morse Micro · HaLowLink 2

A heap-based buffer overflow in the Morse Micro HaLowLink 2 kernel driver allows unauthenticated attackers within radio range to cause system crashes or Remote Code Execution.

Executive summary

A critical heap-based buffer overflow in the Morse Micro HaLowLink 2 kernel driver allows unauthenticated attackers to trigger a kernel panic or execute arbitrary code via malformed beacon frames.

Vulnerability

The morse.ko kernel driver fails to validate the TIM bitmap length in received beacon frames. An unauthenticated attacker within radio range can send a crafted frame to overflow the buffer, leading to potential RCE.

Business impact

The CVSS score of 9.8 indicates that this is a high-priority risk. Successful exploitation could result in full system compromise or a persistent Denial of Service, which is particularly dangerous for industrial or IoT deployments relying on the HaLowLink 2 platform.

Remediation

Immediate Action: Update Morse Micro HaLowLink 2 software to version 2.11.13 or later.

Proactive Monitoring: Review device logs for unusual wireless traffic patterns or repeated kernel stability issues.

Compensating Controls: Given the nature of the attack vector (broadcast beacon frames), physical security and limiting exposure to untrusted wireless environments are the most effective interim measures.

Exploitation status

Public Exploit Available: False

Analyst recommendation

This vulnerability poses a severe threat to system integrity. Administrators must ensure that all devices running the affected Morse Micro software are updated to 2.11.13 to remediate the buffer overflow flaw.