Skip to content
Noroxi

meshtastic records

14 published records for vendor meshtastic.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
57.1%
Median publish → KEV
No record has entered KEV

All records

14 records
  • Meshtastic incorrectly hands malformed packets leads to controlled buffer overflow

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    meshtastic · meshtastic firmwareApr 14, 2025

  • Meshtastic firmware Authentication/Authorization Bypass via MQTT

    CriticalCVSS 9.8No exploitEPSS 0%

    meshtastic · meshtastic firmwareSep 25, 2024

  • Meshtastic allows crafting of specific NodeInfo packets that overwrite any publicKey saved in the NodeDB

    CriticalCVSS 9.8No exploitEPSS 0%

    meshtastic · meshtastic firmwareAug 18, 2025

  • Meshtastic Repeated Public and Private Keypairs

    CriticalCVSS 9.5Proof of conceptEPSS 1%

    meshtastic · meshtastic firmwareJun 19, 2025

  • Meshtastic allows Command Injection in GitHub Action

    HighCVSS 8.0No exploitEPSS 0%

    meshtastic · meshtastic firmwareJul 10, 2025

  • In Meshtastic, an attacker can spoof licensed amateur flag for a node

    HighCVSS 8.2No exploitEPSS 0%

    meshtastic · meshtastic firmwareJan 27, 2026

  • Device crash via malformed MQTT packet when downlink is enabled in Meshtastic device firmware

    HighCVSS 7.5No exploitEPSS 1%

    meshtastic · meshtastic firmwareAug 27, 2024

  • Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failure

    HighCVSS 7.5No exploitEPSS 0%

    meshtastic · meshtastic firmwareJul 19, 2026

  • Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmware

    HighCVSS 7.5No exploitEPSS 0%

    meshtastic · meshtastic firmwareNov 4, 2024

  • Meshtastic crashes via an unimplemented routing module reply

    MediumCVSS 6.5No exploitEPSS 0%

    meshtastic · meshtastic firmwareJul 10, 2025

  • Unauthorized usage of remote hardware module because of missing channel verification

    MediumCVSS 6.4No exploitEPSS 0%

    meshtastic · meshtastic firmwareOct 7, 2024

  • Forged packets over MQTT can show up in direct messages in Meshtastic firmware

    MediumCVSS 5.3No exploitEPSS 0%

    meshtastic · meshtastic firmwareFeb 18, 2025

  • Meshtastic firmware allows forged DMs with no PKC to show up as encrypted

    MediumCVSS 5.3No exploitEPSS 0%

    meshtastic · meshtastic firmwareDec 29, 2025

  • Traceroute_APP responses are not rate-limited.

    LowCVSS 2.7No exploitEPSS 0%

    meshtastic · meshtastic firmwareJul 11, 2025