CVE-2026-7763
Morse Micro · HaLowLink 2
A heap-based buffer overflow in the Morse Micro HaLowLink 2 kernel driver allows unauthenticated attackers within radio range to cause system crashes or Remote Code Execution.
Executive summary
A critical heap-based buffer overflow in the Morse Micro HaLowLink 2 kernel driver allows unauthenticated attackers to trigger a kernel panic or execute arbitrary code via malformed beacon frames.
Vulnerability
The morse.ko kernel driver fails to validate the TIM bitmap length in received beacon frames. An unauthenticated attacker within radio range can send a crafted frame to overflow the buffer, leading to potential RCE.
Business impact
The CVSS score of 9.8 indicates that this is a high-priority risk. Successful exploitation could result in full system compromise or a persistent Denial of Service, which is particularly dangerous for industrial or IoT deployments relying on the HaLowLink 2 platform.
Remediation
Immediate Action: Update Morse Micro HaLowLink 2 software to version 2.11.13 or later.
Proactive Monitoring: Review device logs for unusual wireless traffic patterns or repeated kernel stability issues.
Compensating Controls: Given the nature of the attack vector (broadcast beacon frames), physical security and limiting exposure to untrusted wireless environments are the most effective interim measures.
Exploitation status
Public Exploit Available: False
Analyst recommendation
This vulnerability poses a severe threat to system integrity. Administrators must ensure that all devices running the affected Morse Micro software are updated to 2.11.13 to remediate the buffer overflow flaw.