Skip to main content

Vendor/product archive

meshtastic / meshtastic_firmware CVEs

Beta · best-effort

13 CVEs tagged to meshtastic / meshtastic_firmware3 Critical, 3 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2025-55292

Published Jan 28, 2026

Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by their NodeID, generated from the MAC address, rather than th…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-53627

Published Dec 29, 2025

Meshtastic is an open source mesh networking solution. The Meshtastic firmware (starting from version 2.5) introduces asymmetric encryption (PKI) for direct messages, but when the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55293

Published Aug 18, 2025

Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publicKey first, then overwrite it with a new key. First sending…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-47065

Published Jul 11, 2025

Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not rate limited. Given that there are SNR measurements attrib…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-53637

Published Jul 10, 2025

Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_request_target event, which has extensive permissions, and can be…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24798

Published Jul 10, 2025

Meshtastic is an open source mesh networking solution. From 1.2.1 until 2.6.2, a packet sent to the routing module that contains want_response==true causes a crash. This can lead…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-52464

Published Jun 19, 2025

Meshtastic is an open source mesh networking solution. In versions from 2.5.0 to before 2.6.11, the flashing procedure of several hardware vendors was resulting in duplicated publ…

CVSS 9.5 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-24797

Published Apr 15, 2025

Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protobuf data can result in an attacker-controlled buffer overflo…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-21608

Published Feb 18, 2025

Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able to appear as a DM in client to a node even though they were…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-51500

Published Nov 4, 2024

Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets claiming to be from the special broadcast address (0xFFFFFF…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47079

Published Oct 7, 2024

Meshtastic is an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Meshtastic firmware is an open source firmware implementation fo…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47078

Published Sep 25, 2024

Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. Nodes can…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45038

Published Aug 27, 2024

Meshtastic device firmware is a firmware for meshtastic devices to run an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Meshtas…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1