CVE-2026-7763
Last modified
CVE-2026-7763 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon frame containing a malformed Traffic Indication Map (TIM) Information Element. The function morse_page_slicing_process_tim_element() in page_slicing.c derives the TIM bitmap length directly from a received IE field without validating it against the fixed-size destination buffer before passing it to memset and memcpy operations, allowing up to 252 bytes of attacker-controlled data to be written beyond the buffer boundary. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon frame containing a malformed Traffic Indication Map (TIM) Information Element. The function morse_page_slicing_process_tim_element() in page_slicing.c derives the TIM bitmap length directly from a received IE field without validating it against the fixed-size destination buffer before passing it to memset and memcpy operations, allowing up to 252 bytes of attacker-controlled data to be written beyond the buffer boundary. Because beacons are broadcast frames processed during passive scanning, no authentication, association, or user interaction is required.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Morse Micro | HaLowLink 2 | < 2.11.13 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-7763?
How severe is CVE-2026-7763?
How do I fix CVE-2026-7763?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-77615Paella Player is a set of libraries to create a multi stream…8.7
- CVE-2026-77616Semantic MediaWiki is a free, open-source extension to Media…6.1
- CVE-2026-77619Vector is a high-performance observability data pipeline. Fr…8.7
- CVE-2026-7762A heap-based buffer overflow vulnerability in the dot11ah.ko…9.8
- CVE-2026-77620Vector is a high-performance observability data pipeline. Fr…8.7
- CVE-2026-77621Vector is a high-performance observability data pipeline. Fr…9.3
- CVE-2026-77633Cloudreve is a self-hosted file management and sharing syste…7.1
- CVE-2026-77634CakePHP is a rapid development framework for PHP. Prior to v…8.2
- CVE-2026-77635CakePHP is a rapid development framework for PHP. Prior to v…9.2
- CVE-2026-77637Cloudreve is a self-hosted file management and sharing syste…3.8
- CVE-2026-77638Tor before 0.4.9.11 is prone to a race condition where in ju…9
- CVE-2026-77639Tor before 0.4.9.9 was prone to a compression bomb bypass wh…5.3
Are you affected by CVE-2026-7763?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
