meshtastic kayıtları
meshtastic üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %57,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-287 Improper Authentication2
- CWE-1287 Improper Validation of Specified Type of Input1
- CWE-138 Improper Neutralization of Special Elements1
- CWE-20 Improper Input Validation1
- CWE-331 Insufficient Entropy1
- CWE-345 Insufficient Verification of Data Authenticity1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2025-24797Kavram kanıtı | Meshtastic incorrectly hands malformed packets leads to controlled buffer overflowmeshtastic · meshtastic firmware · CWE-119 | Kritik9,8 | — | %0,9 | 14 Nis 2025 |
39İzleyin | CVE-2024-47078İstismar yok | Meshtastic firmware Authentication/Authorization Bypass via MQTTmeshtastic · meshtastic firmware · CWE-287 | Kritik9,8 | — | %0,5 | 25 Eyl 2024 |
39İzleyin | CVE-2025-55293İstismar yok | Meshtastic allows crafting of specific NodeInfo packets that overwrite any publicKey saved in the NodeDBmeshtastic · meshtastic firmware · CWE-287 | Kritik9,8 | — | %0,4 | 18 Ağu 2025 |
38İzleyin | CVE-2025-52464Kavram kanıtı | Meshtastic Repeated Public and Private Keypairsmeshtastic · meshtastic firmware · CWE-331 | Kritik9,5 | — | %0,6 | 19 Haz 2025 |
32İzleyin | CVE-2025-53637İstismar yok | Meshtastic allows Command Injection in GitHub Actionmeshtastic · meshtastic firmware · CWE-78 | Yüksek8,0 | — | %0,3 | 10 Tem 2025 |
32İzleyin | CVE-2025-55292İstismar yok | In Meshtastic, an attacker can spoof licensed amateur flag for a nodemeshtastic · meshtastic firmware · CWE-348 | Yüksek8,2 | — | %0,1 | 27 Oca 2026 |
30İzleyin | CVE-2024-45038İstismar yok | Device crash via malformed MQTT packet when downlink is enabled in Meshtastic device firmwaremeshtastic · meshtastic firmware · CWE-755 | Yüksek7,5 | — | %0,6 | 27 Ağu 2024 |
30İzleyin | CVE-2026-42566İstismar yok | Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failuremeshtastic · meshtastic firmware · CWE-20 | Yüksek7,5 | — | %0,5 | 19 Tem 2026 |
30İzleyin | CVE-2024-51500İstismar yok | Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmwaremeshtastic · meshtastic firmware · CWE-138 | Yüksek7,5 | — | %0,4 | 4 Kas 2024 |
26İzleyin | CVE-2025-24798İstismar yok | Meshtastic crashes via an unimplemented routing module replymeshtastic · meshtastic firmware · CWE-617 | Orta6,5 | — | %0,4 | 10 Tem 2025 |
25İzleyin | CVE-2024-47079İstismar yok | Unauthorized usage of remote hardware module because of missing channel verificationmeshtastic · meshtastic firmware · CWE-345 | Orta6,4 | — | %0,2 | 7 Eki 2024 |
21İzleyin | CVE-2025-21608İstismar yok | Forged packets over MQTT can show up in direct messages in Meshtastic firmwaremeshtastic · meshtastic firmware · CWE-668 | Orta5,3 | — | %0,4 | 18 Şub 2025 |
21İzleyin | CVE-2025-53627İstismar yok | Meshtastic firmware allows forged DMs with no PKC to show up as encryptedmeshtastic · meshtastic firmware · CWE-1287 | Orta5,3 | — | %0,2 | 29 Ara 2025 |
10İzleyin | CVE-2024-47065İstismar yok | Traceroute_APP responses are not rate-limited.meshtastic · meshtastic firmware · CWE-799 | Düşük2,7 | — | %0,2 | 11 Tem 2025 |
- CVE-2025-2479739İzleyin
Meshtastic incorrectly hands malformed packets leads to controlled buffer overflow
KritikCVSS 9,8Kavram kanıtıEPSS %1meshtastic · meshtastic firmware14 Nis 2025
- CVE-2024-4707839İzleyin
Meshtastic firmware Authentication/Authorization Bypass via MQTT
KritikCVSS 9,8İstismar yokEPSS %0meshtastic · meshtastic firmware25 Eyl 2024
- CVE-2025-5529339İzleyin
Meshtastic allows crafting of specific NodeInfo packets that overwrite any publicKey saved in the NodeDB
KritikCVSS 9,8İstismar yokEPSS %0meshtastic · meshtastic firmware18 Ağu 2025
- CVE-2025-5246438İzleyin
Meshtastic Repeated Public and Private Keypairs
KritikCVSS 9,5Kavram kanıtıEPSS %1meshtastic · meshtastic firmware19 Haz 2025
- CVE-2025-5363732İzleyin
Meshtastic allows Command Injection in GitHub Action
YüksekCVSS 8,0İstismar yokEPSS %0meshtastic · meshtastic firmware10 Tem 2025
- CVE-2025-5529232İzleyin
In Meshtastic, an attacker can spoof licensed amateur flag for a node
YüksekCVSS 8,2İstismar yokEPSS %0meshtastic · meshtastic firmware27 Oca 2026
- CVE-2024-4503830İzleyin
Device crash via malformed MQTT packet when downlink is enabled in Meshtastic device firmware
YüksekCVSS 7,5İstismar yokEPSS %1meshtastic · meshtastic firmware27 Ağu 2024
- CVE-2026-4256630İzleyin
Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failure
YüksekCVSS 7,5İstismar yokEPSS %0meshtastic · meshtastic firmware19 Tem 2026
- CVE-2024-5150030İzleyin
Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmware
YüksekCVSS 7,5İstismar yokEPSS %0meshtastic · meshtastic firmware4 Kas 2024
- CVE-2025-2479826İzleyin
Meshtastic crashes via an unimplemented routing module reply
OrtaCVSS 6,5İstismar yokEPSS %0meshtastic · meshtastic firmware10 Tem 2025
- CVE-2024-4707925İzleyin
Unauthorized usage of remote hardware module because of missing channel verification
OrtaCVSS 6,4İstismar yokEPSS %0meshtastic · meshtastic firmware7 Eki 2024
- CVE-2025-2160821İzleyin
Forged packets over MQTT can show up in direct messages in Meshtastic firmware
OrtaCVSS 5,3İstismar yokEPSS %0meshtastic · meshtastic firmware18 Şub 2025
- CVE-2025-5362721İzleyin
Meshtastic firmware allows forged DMs with no PKC to show up as encrypted
OrtaCVSS 5,3İstismar yokEPSS %0meshtastic · meshtastic firmware29 Ara 2025
- CVE-2024-4706510İzleyin
Traceroute_APP responses are not rate-limited.
DüşükCVSS 2,7İstismar yokEPSS %0meshtastic · meshtastic firmware11 Tem 2025