Terms and conditions

Website terms of use

OVERVIEW

This Policy, together with the documents referred to in it (collectively, the “Terms of Use”) applies to the Morse Micro website (www.morsemicro.com), and all associated sites existing as subdomains or linked to or from www.morsemicro.com by Morse Micro, its subsidiaries and affiliates, (collectively, “Morse Micro,” “we,” or “us”), including Morse Micro sites around the world (collectively, the “Site”). The Site is the property of Morse Micro and its licensors, and these Terms of Use govern your use of the Site, including accessing, browsing, registering, using and downloading.

By using the site, you agree to these terms of use. If you do not agree, do not use the site.

OTHER POLICIES

Readers of this policy are encouraged to read this document in conjunction with other relevant company policies, including:

  • Privacy policy
  • Cookie policy

Each of the above may be changed from time to time and are effective immediately upon posting such changes on the Site.

If you obtain trial or evaluation products from our Site, then Morse Micro’s obligations, if any, concerning such products are governed solely by the applicable pre-existing agreements – nothing on this Site should be construed to alter such agreements.

ACCESSING THE SITE AND RESTRICTED ACTIVITIES

You may not use any “deep-link”, “page-scrape”, “robot”, “spider” or other automatic devices, programs, algorithms or methodologies, or any similar or equivalent manual processes, to access, acquire, copy or monitor any portion of the Site or any content, or in any way obtain or attempt to obtain any materials, documents or information through any means not purposely made available through the Site.

You may not attempt to gain unauthorised access to any portion or feature of the Site, or any other systems or networks connected to the Site or any Morse Micro server, or any of the services offered on or through the Site, by hacking, password “mining” or any other illegitimate means.

You may not probe, scan or test the vulnerability of the Site or any network connected to the Site, nor breach the security or authentication measures on the Site or any network connected to the Site. You may not reverse look-up, trace or seek to trace any information on any other user of or visitor to the Site, or any other customer of Morse Micro, including any Morse Micro, account not owned by you, to its source, or exploit the Site or any service or information made available or offered by or through the Site, in any way where the purpose is to reveal any information, including but not limited to personal identification or information, other than your information, as provided for by the Site.

You agree not to use any device, software or routine to interfere or attempt to interfere with the proper working of the Site or any transaction being conducted on the Site, or with any other person’s use of the Site.

You may not use the Site or any content for any purpose that is unlawful or prohibited by these Terms of Use or to solicit the performance of any illegal activity or other activity which infringes the rights of Morse Micro or others.

You further agree (i) not to reproduce, duplicate, copy or re-sell any part of the Site and (ii) not to access without authority, interfere with, damage or disrupt any part of the Site, any software used in the provision of the Site or any equipment or network or software owned or used by any third party.

You are prohibited from using the Site, including the Content, in any way that competes with Morse Micro’s business.

INTELLECTUAL PROPERTY RIGHTS

All content, software, data and intellectual property on or relating to the Site is the property of Morse Micro. None of the software, data or content found on the Site may be reproduced, republished, distributed, posted, sold, transferred or modified in any way without our prior express written permission. All intellectual property including but not limited to trademarks, logos and service marks displayed on the Site is registered by Morse Micro and protected throughout the world. No licence, right or interest in any Morse Micro intellectual property is granted to you.

You may use the information on Morse Micro products and services (such as data sheets, articles, whitepapers and similar materials) purposefully made available by Morse Micro for downloading from the Site, provided that you (1) do not remove any proprietary notice language in all copies of such documents, (2) use such information only for your personal, non-commercial purpose, (3) make no modifications to any such information and (4) do not make any additional representations or warranties relating to such documents. You may print off reasonable copies of any page(s) from the Site for your personal use and you may draw the attention of other users within your organisation to content posted on the Site.

You may quote short portions of content on the Site, but not copy substantial portions of the content of an article or webpage on the Site or copy same in their entirety, provided that (i) you credit Morse Micro at the end of such quote, and (ii) if you publish the quote on a website, you include an attribution link to www.morsemicro.com from within such article.

Should you wish to make use of any of the content on the Site other than as expressly permitted above, please contact Morse Micro directly, via phone, email or website contact form.

NO RELIANCE ON INFORMATION

The opinions expressed by Morse Micro employees on any blogs or within any web-based content do not represent or necessarily correspond to the opinions of Morse Micro. We will not be responsible for any direct or indirect damages or losses caused or alleged to have been caused as a result of your use or reliance on such information.

LIMITATION OF LIABILITY

Except where prohibited by law, Morse Micro will not be liable to any user of the Site for any loss or damage, whether in contract, tort (including but not limited to negligence), breach of statutory duty or otherwise, even if foreseeable, arising under or in connection with including (but not limited to) the following:

  • any use of this Site or content found therein
  • any failure or delay in the use of or inability to use the Site and whether the Site is available on an uninterrupted, secure, or error-free basis
  • an act or omission by Morse Micro
  • the completeness, accuracy, availability, timeliness, security or reliability of the Site or any content found therein inadequacy of the Site to meet your requirements
  • incompatibility of the Site with any of your equipment, software or telecommunications links
  • the provision of or failure to provide services
  • any information, products, services and related graphics obtained through the Site

VIOLATIONS OF THESE TERMS OF USE

Morse Micro may disclose any information we have about you (including your identity) if we determine that such disclosure is necessary for any investigation or complaint regarding your use of the Site, or to identify, contact or bring legal action against someone who may be causing injury to or interference with (either intentionally or unintentionally) Morse Micro’ rights or property, or the rights or property of visitors to or users of the Site, including Morse Micro’ customers. Morse Micro reserves the right at all times to disclose any information that Morse Micro deems necessary to comply with any applicable law, regulation, legal process or governmental request.

You acknowledge and agree that Morse Micro may preserve any transmittal or communication by you with Morse Micro through the Site or any service offered on or through the Site, and may also disclose such data if required to do so by law or if Morse Micro determines that such preservation or disclosure is reasonably necessary to (1) comply with legal process, (2) enforce these Terms of Use, (3) respond to claims that any such data violates the rights of others, or (4) protect the rights, property or personal safety of Morse Micro, its employees, users of or visitors to the Site, and the public.

You agree that Morse Micro may, in its sole discretion and without prior notice, terminate your access to the Site and/or block your future access to the Site for any or no reason, including if we determine that you have violated these Terms of Use or other agreements or guidelines which may be associated with your use of the Site. You also agree that any violation by you of these Terms of Use will constitute an unlawful and unfair business practice, and will cause irreparable harm to Morse Micro, for which monetary damages would be inadequate, and you consent to Morse Micro obtaining any injunctive or equitable relief that Morse Micro deems necessary or appropriate in such circumstances.

These remedies are in addition to any other remedies Morse Micro may have at law or in equity.

You agree that Morse Micro may, in its sole discretion and without prior notice, terminate your access to the Site, for any or no reason, which includes (but is not limited to) (1) requests by law enforcement or other government agencies, (2) a request by you (self-initiated account deletions), (3) discontinuance or material modification of the Site or any service offered on or through the Site, or (4) unexpected technical issues or problems.

LINKING TO THE SITE

You may link to our home page, provided that you do so in a way that is fair and legal and does not damage our reputation or take advantage of it.

You must not establish a link in any such way that suggests a form of association, approval or endorsement with or by Morse Micro where none exists.

The Site must not be framed on any other site, nor may you create a link to any part of our Site other than the home page.

Morse Micro reserves the right to withdraw linking permissions at any time and without notice.

Should you wish to make use of any of the content on the Site other than set out above, please contact Morse Micro directly, via phone, email or website contact form.

THIRD-PARTY LINKS AND RESOURCES ON THE SITE

Where our Site contains links to other sites and resources provided by third parties, these links are provided for your information only. You acknowledge that we have no control over the content of those sites or resources.

APPLICABLE LAW

These Terms of Use, their subject matter and construction (and any non-contractual disputes or claims) are governed by the laws of New South Wales, Australia, and you agree to the non-exclusive jurisdiction of these courts.

We reserve the right to seek injunctive, or any other equitable relief, in any courts of competent jurisdiction should we, in our sole opinion, consider this to be necessary.

If a provision of these Terms is held to be void, invalid, illegal or unenforceable, that provision must be read down as narrowly as necessary to allow it to be valid or enforceable. If it is not possible to read down a provision (in whole or in part), that provision (or that part of that provision) is severed from these Terms without affecting the validity or enforceability of the remainder of that provision or the other provisions in these Terms.

CHANGES TO THESE TERMS, THE SITE, AND OUR PRODUCTS AND SERVICES

We may revise these Terms of Use and any other applicable or associated policies in our sole discretion at any time. It is your responsibility to review this page for changes as such changes will be binding upon you and your continued use of the Site will mean that you accept and agree to the changes. No notice of any changes will be given.

We may modify, update, suspend or terminate operation of or access to the Site from time to time without notice, including for clarity changing the content at any time. We may interrupt the operation of the Site, or any portion of the Site, as necessary to perform routine or non-routine maintenance, error correction, or other changes.

Morse Micro may make changes to any products offered on the Site, or to the applicable prices for any such products or services, at any time, without notice. The materials on the Site concerning products may be out of date, and Morse Micro does not commit to updating the materials on the Site.

Security

At Morse Micro, we’re committed to building secure, robust wireless solutions. We recognize that strong collaboration with security researchers, customers, and partners is essential to maintaining the trust and safety of our products and ecosystem.

This page is the entry point to Morse Micro’s security resources.

Report a Security Issue

If you believe you have identified a security vulnerability in a Morse Micro product, please see our Security Disclosure Policy for the process to report it confidentially to our Product Security Incident Response Team (PSIRT).

For urgent reports, contact security@morsemicro.com (encrypted with our PGP key is preferred for sensitive information).

Security Advisories

Published advisories detailing security vulnerabilities affecting Morse Micro products, along with affected versions, fixed versions, and mitigation guidance, are available on the Security Advisories page.

Regulatory and Compliance Statements

  • PSTI Statement – UK Product Security and Telecommunications Infrastructure Act compliance statement.
  • Cyber Resilience Act (CRA) – Morse Micro tracks the EU CRA and engages with module partners on their conformance dossiers. Customers requiring vulnerability handling information for CRA compliance should refer to our Security Disclosure Policy and the Security Advisories Feed.

Coordinated Disclosure and Standards

Morse Micro’s security disclosure process follows international standards:

  • ISO/IEC 29147 – Vulnerability disclosure
  • ISO/IEC 30111 – Vulnerability handling processes
  • FIRST PSIRT Services Framework

CVE identifiers for vulnerabilities in Morse Micro products are assigned by Bugcrowd in their capacity as a CVE Numbering Authority (CNA), operating in coordination with Morse Micro’s PSIRT.

Contact

Security Advisories

This page lists all published security advisories for Morse Micro products. Each advisory is identified by a Morse Micro Security Advisory (MM-SA) number and references one or more CVE identifiers.

For information on how to report a vulnerability, see our Security Disclosure Policy.

Customers with active support agreements who require advance notice of advisories under embargo should contact their Morse Micro account team or security@morsemicro.com.

Advisory Feed

An Atom feed of advisories is available at feed.xml for partner security teams to subscribe to.

Published Advisories

Advisory CVE Title Severity Published
MM-SA-2026-001 CVE-2026-7763 Pre-authentication heap buffer overflow in morse.ko TIM IE processing High 4th June 2026
MM-SA-2026-002 CVE-2026-7762 Pre-authentication heap buffer overflow in dot11ah.ko S1G Capabilities IE processing High 4th June 2026
MM-SA-2026-003 CVE-2026-7764 Pre-authentication out-of-bounds read in morse.ko Vendor IE processing Medium 21st May 2026

Naming Convention

Advisory identifiers follow the format MM-SA-YYYY-NNN where YYYY is the year of publication and NNN is a zero-padded sequence number within that year.

MM-SA-2026-003 Security Advisory

Out-of-bounds read in morse.ko Vendor IE processing

CVE CVE-2026-7764
Severity Medium (CVSS v3.1 6.5)
Fixed in HaLowLink 2 software version 2.11.12
Status Resolved

Summary

An out-of-bounds read in the morse.ko HaLow Wi-Fi kernel driver allows an unauthenticated attacker within radio range to disclose a small amount of kernel heap memory or cause a denial of service via a crafted 802.11ah beacon or probe response containing a malformed Vendor Information Element.

Affected products

Product Affected versions Fixed version
HaLowLink 2 All versions prior to 2.11.12 2.11.12

Customers using morse.ko in their own Linux integrations should treat their integration as affected if the driver source corresponds to a Morse Micro driver release predating 2.11.12. Contact security@morsemicro.com for patched source.

Action

Upgrade HaLowLink 2 software to 2.11.12 or later.

Acknowledgements

Reported to Morse Micro through Bugcrowd. Morse Micro thanks the researcher for responsible disclosure.

References

MM-SA-2026-002 Security Advisory

Heap buffer overflow in dot11ah.ko S1G Capabilities IE processing

CVE CVE-2026-7762
Severity High (CVSS v3.1 8.8)
Fixed in HaLowLink 2 software version 2.11.13
Status Resolved

Summary

A heap buffer overflow in the dot11ah.ko HaLow Wi-Fi kernel driver allows an unauthenticated attacker within radio range to cause a denial of service or potentially achieve remote code execution via a crafted 802.11ah beacon or probe response containing a malformed S1G Capabilities Information Element.

Affected products

Product Affected versions Fixed version
HaLowLink 2 All versions prior to 2.11.13 2.11.13

Customers using dot11ah.ko in their own Linux integrations should treat their integration as affected if the driver source corresponds to a Morse Micro driver release predating 2.11.13. Contact security@morsemicro.com for patched source.

Action

Upgrade HaLowLink 2 software to 2.11.13 or later.

Acknowledgements

Reported to Morse Micro through Bugcrowd. Morse Micro thanks the researcher for responsible disclosure.

References

Security Disclosure

At Morse Micro, we’re committed to building secure, robust wireless solutions. We recognize that strong collaboration with security researchers, customers, and partners is essential to maintaining the trust and safety of our products and ecosystem.

We take security vulnerabilities seriously and encourage responsible disclosure. Our Product Security Incident Response Team (PSIRT) ensures reports are handled professionally, confidentially, and in line with global industry standards.

Reporting Security Vulnerabilities

We welcome reports of potential security vulnerabilities that may affect:

  • Morse Micro chipsets (e.g., MM6108, MM8108)
  • Reference designs (e.g., HaLowLink 1, HaLowLink 2)
  • Software SDKs, OpenWRT builds, and firmware
  • Online developer documentation and drivers
Out of Scope
  • Non-security bugs or usability issues
  • End-user apps developed by third parties
  • Experimental evaluation kits (e.g., EKH01, EKH05, EKH19)
Working with Researchers

We value collaboration with the security community and ask that all research and reporting be conducted responsibly.

Researchers are expected to:
  • Respect user privacy and data integrity — do not access, modify, or delete information that does not belong to you.
  • Maintain system availability — avoid denial-of-service, brute force, social engineering, or physical attacks.
  • Remain within scope — focus only on Morse Micro products and software listed above.
  • Disclose responsibly — allow us sufficient time to investigate and remediate before making findings public.
  • Provide clear and reproducible details so our engineers can validate the issue efficiently.
In return, Morse Micro will:
  • Acknowledge receipt of your report promptly and provide ongoing status updates.
  • Handle submissions with professionalism, confidentiality, and fairness.
  • Offer public recognition (with your consent) where appropriate, such as in advisories or release notes.
  • Uphold our safe harbor commitment if you act in good faith.
  • Report a Security Issue
If you believe you have identified a security issue, please complete the form below.
Alternatively, you can contact our PSIRT team directly:
Include the following details:
  • Product name(s) and version(s) affected
  • Description of the vulnerability
  • Steps to reproduce or proof-of-concept (if available)
  • Potential impact and/or suggested mitigation
  • Your preferred contact method

All reports are treated with confidentiality and respect.

PSTI Statement of Compliance

Morse Micro confirms that our consumer-connectable products sold in the United Kingdom comply with the security requirements set out in the Product Security and Telecommunications Infrastructure (PSTI) Regulations 2023.

Security Requirements

Our products meet the applicable PSTI security controls, including the requirement for unique or user-defined passwords and protection against common, easily exploitable vulnerabilities.

Security Update Support

Each product is supported with security updates for a defined support period.
The applicable support period, including the method for determining its end date, is listed in the product’s Statement of Compliance or related documentation. Up-to-date information concerning the defined support periods for the entire Morse Micro product range are listed in: Morse Micro PSTI Statement of Compliance.

Reporting Security Issues

Potential security vulnerabilities can be reported to our Product Security Incident Response Team (PSIRT) using the contact details on our security disclosure page.

We acknowledge reports promptly and provide follow-up communication as the issue is investigated and resolved.