CVE-2025-55292
- EPSS 0.02%
- Veröffentlicht 27.01.2026 23:28:28
- Zuletzt bearbeitet 02.03.2026 21:17:27
Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by their NodeID, generated from the MAC address, rather than their public key. This aspect downgrades the security, specifically by ab...
CVE-2025-53627
- EPSS 0.03%
- Veröffentlicht 29.12.2025 16:18:29
- Zuletzt bearbeitet 26.02.2026 19:11:17
Meshtastic is an open source mesh networking solution. The Meshtastic firmware (starting from version 2.5) introduces asymmetric encryption (PKI) for direct messages, but when the `pki_encrypted` flag is missing, the firmware silently falls back to l...
CVE-2025-55293
- EPSS 0.06%
- Veröffentlicht 18.08.2025 17:24:35
- Zuletzt bearbeitet 17.10.2025 17:48:30
Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publicKey first, then overwrite it with a new key. First sending a empty key bypasses 'if (p.public_key.size > 0) {', clearing the exis...
CVE-2024-47065
- EPSS 0.02%
- Veröffentlicht 11.07.2025 17:00:44
- Zuletzt bearbeitet 22.08.2025 16:01:46
Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not rate limited. Given that there are SNR measurements attributed to each received transmission, this is a guaranteed way to get a r...
- EPSS 0.04%
- Veröffentlicht 10.07.2025 21:31:44
- Zuletzt bearbeitet 22.08.2025 16:02:16
Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_request_target event, which has extensive permissions, and can be initiated by an attacker who forked the repository and created a pull ...
CVE-2025-24798
- EPSS 0.01%
- Veröffentlicht 10.07.2025 21:22:30
- Zuletzt bearbeitet 22.08.2025 16:02:31
Meshtastic is an open source mesh networking solution. From 1.2.1 until 2.6.2, a packet sent to the routing module that contains want_response==true causes a crash. This can lead to a degradation of service for nodes within range of a malicious sende...
CVE-2025-52464
- EPSS 0.08%
- Veröffentlicht 19.06.2025 15:10:18
- Zuletzt bearbeitet 09.10.2025 16:52:14
Meshtastic is an open source mesh networking solution. In versions from 2.5.0 to before 2.6.11, the flashing procedure of several hardware vendors was resulting in duplicated public/private keys. Additionally, the Meshtastic was failing to properly i...
CVE-2025-24797
- EPSS 1.97%
- Veröffentlicht 14.04.2025 23:25:19
- Zuletzt bearbeitet 03.10.2025 15:31:58
Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protobuf data can result in an attacker-controlled buffer overflow, allowing an attacker to hijack execution flow, potentially resulting...
CVE-2025-21608
- EPSS 0.07%
- Veröffentlicht 18.02.2025 19:15:25
- Zuletzt bearbeitet 23.09.2025 19:20:35
Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able to appear as a DM in client to a node even though they were not decoded with PKC. This issue has been addressed in version 2.5.19 ...
CVE-2024-51500
- EPSS 0.09%
- Veröffentlicht 04.11.2024 23:15:04
- Zuletzt bearbeitet 15.10.2025 17:53:26
Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets claiming to be from the special broadcast address (0xFFFFFFFF) which could result in unexpected behavior and potential for DDoS at...