Security Disclosures and Vulnerability Reporting

Disclosures

We continuously monitor and assess reported security issues. This section provides information on confirmed security vulnerabilities affecting Sequans Products.

Each advisory includes the impacted assets, severity assessment, and remediation status.
We aim to provide accurate and up-to-date information to help customers assess potential risks and apply appropriate mitigations.

For questions regarding a specific advisory, please contact: sequans.com/contact

 

Vulnerability Affected Product(s) Additional Information and Recommendations
SQNSEC-2026-001 – CVE-2023-38039 GC02S1 (all variants) /  GM02S (all variants) / SKY66431(all variants) Please refer to the corresponding Security/Information Bulletin (PDF) for details
SQNSEC-2026-002 – CVE-2020-36325 GC02S1 (all variants) /  GM02S (all variants) / SKY66431(all variants) Please refer to the corresponding Security/Information Bulletin (PDF) for details
SQNSEC-2026-003 – CVE-2026-5194 GC02S1 (all variants) /  GM02S (all variants) / SKY66431(all variants) Please refer to the corresponding Security/Information Bulletin (PDF) for details
SQNSEC-2026-005 – CVE-2021-27417 GC02S1 (all variants) /  GM02S (all variants) / SKY66431(all variants) Please refer to the corresponding Security/Information Bulletin (PDF) for details
SQNSEC-2026-006 – CVE-2023-46218 GC02S1 (all variants) /  GM02S (all variants) / SKY66431(all variants) Please refer to the corresponding Security/Information Bulletin (PDF) for details
SQNSEC-2026-007 – CVE-2024-7264 GC02S1 (all variants) /  GM02S (all variants) / SKY66431(all variants) Please refer to the corresponding Security/Information Bulletin (PDF) for details

 

Responsible Disclosure Policy

This platform may be used to report suspected vulnerability affecting Sequans Products. Reports submitted in good faith for academic or private research purposes are welcomed and will not be subject to penalties. However, any intentional, malicious, or repeated attacks are strictly prohibited and may be reported to the appropriate authorities in accordance with applicable laws.

 

Report on the issue

To enable efficient analysis and resolution, please include the following information:

  • Affected Sequans product(s), including version numbers
  • Type of vulnerability or security issue (e.g., spoofing, tampering, remote code execution, information disclosure, denial of service, privilege escalation)
  • Severity assessment (if known)
  • How and when the vulnerability/security issue was discovered
  • Detailed steps to reproduce the issue, including technical information
  • Supporting materials such as logs, screenshots, images, or exploit code

Please ensure that only information necessary for investigation is provided. Do not include personal or sensitive personal data. All personal information shared will be handled in accordance with the Sequans Communications Privacy Policy.

 

How to report a Security Vulnerability

If you believe you have identified a potential vulnerability or security issue in one of our Products, please contact us and we will send you the form to submit.

Reporters may choose to remain anonymous. Sequans only require a valid email address to establish a communication channel regarding the reported issue. No additional personal information is required.

 

Follow-up actions

Each submission will be carefully reviewed by Sequans. After receiving your report, the following steps will be taken:

  • Assessment and prioritization of the vulnerability based on its potential impact and exposure
  • Sequans will acknowledge receipt of vulnerability reports within a reasonable timeframe.
  • Possible requests for additional information to support investigation and resolution
  • If required, and where the vulnerability has been confirmed, implementation of corrective actions, notification to relevant stakeholders (including customers and/or regulatory authorities), or other appropriate measures depending on the nature of the issue

To reduce the risk of exploitation, Sequans request that reporters refrain from publicly disclosing vulnerabilities until an appropriate remediation or mitigation is available, and coordinated disclosure has been agreed upon.

Acknowledgements

We sincerely thank all individuals and organizations that contribute to improving the security of Sequans Products by responsibly reporting vulnerabilities.