meshtastic records
14 published records for vendor meshtastic.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 57.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication2
- CWE-1287 Improper Validation of Specified Type of Input1
- CWE-138 Improper Neutralization of Special Elements1
- CWE-20 Improper Input Validation1
- CWE-331 Insufficient Entropy1
- CWE-345 Insufficient Verification of Data Authenticity1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-24797Proof of concept | Meshtastic incorrectly hands malformed packets leads to controlled buffer overflowmeshtastic · meshtastic firmware · CWE-119 | Critical9.8 | — | 0.9% | Apr 14, 2025 |
39Monitor | CVE-2024-47078No exploit | Meshtastic firmware Authentication/Authorization Bypass via MQTTmeshtastic · meshtastic firmware · CWE-287 | Critical9.8 | — | 0.5% | Sep 25, 2024 |
39Monitor | CVE-2025-55293No exploit | Meshtastic allows crafting of specific NodeInfo packets that overwrite any publicKey saved in the NodeDBmeshtastic · meshtastic firmware · CWE-287 | Critical9.8 | — | 0.4% | Aug 18, 2025 |
38Monitor | CVE-2025-52464Proof of concept | Meshtastic Repeated Public and Private Keypairsmeshtastic · meshtastic firmware · CWE-331 | Critical9.5 | — | 0.6% | Jun 19, 2025 |
32Monitor | CVE-2025-53637No exploit | Meshtastic allows Command Injection in GitHub Actionmeshtastic · meshtastic firmware · CWE-78 | High8.0 | — | 0.3% | Jul 10, 2025 |
32Monitor | CVE-2025-55292No exploit | In Meshtastic, an attacker can spoof licensed amateur flag for a nodemeshtastic · meshtastic firmware · CWE-348 | High8.2 | — | 0.1% | Jan 27, 2026 |
30Monitor | CVE-2024-45038No exploit | Device crash via malformed MQTT packet when downlink is enabled in Meshtastic device firmwaremeshtastic · meshtastic firmware · CWE-755 | High7.5 | — | 0.6% | Aug 27, 2024 |
30Monitor | CVE-2026-42566No exploit | Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failuremeshtastic · meshtastic firmware · CWE-20 | High7.5 | — | 0.5% | Jul 19, 2026 |
30Monitor | CVE-2024-51500No exploit | Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmwaremeshtastic · meshtastic firmware · CWE-138 | High7.5 | — | 0.4% | Nov 4, 2024 |
26Monitor | CVE-2025-24798No exploit | Meshtastic crashes via an unimplemented routing module replymeshtastic · meshtastic firmware · CWE-617 | Medium6.5 | — | 0.4% | Jul 10, 2025 |
25Monitor | CVE-2024-47079No exploit | Unauthorized usage of remote hardware module because of missing channel verificationmeshtastic · meshtastic firmware · CWE-345 | Medium6.4 | — | 0.2% | Oct 7, 2024 |
21Monitor | CVE-2025-21608No exploit | Forged packets over MQTT can show up in direct messages in Meshtastic firmwaremeshtastic · meshtastic firmware · CWE-668 | Medium5.3 | — | 0.4% | Feb 18, 2025 |
21Monitor | CVE-2025-53627No exploit | Meshtastic firmware allows forged DMs with no PKC to show up as encryptedmeshtastic · meshtastic firmware · CWE-1287 | Medium5.3 | — | 0.2% | Dec 29, 2025 |
10Monitor | CVE-2024-47065No exploit | Traceroute_APP responses are not rate-limited.meshtastic · meshtastic firmware · CWE-799 | Low2.7 | — | 0.2% | Jul 11, 2025 |
- CVE-2025-2479739Monitor
Meshtastic incorrectly hands malformed packets leads to controlled buffer overflow
CriticalCVSS 9.8Proof of conceptEPSS 1%meshtastic · meshtastic firmwareApr 14, 2025
- CVE-2024-4707839Monitor
Meshtastic firmware Authentication/Authorization Bypass via MQTT
CriticalCVSS 9.8No exploitEPSS 0%meshtastic · meshtastic firmwareSep 25, 2024
- CVE-2025-5529339Monitor
Meshtastic allows crafting of specific NodeInfo packets that overwrite any publicKey saved in the NodeDB
CriticalCVSS 9.8No exploitEPSS 0%meshtastic · meshtastic firmwareAug 18, 2025
- CVE-2025-5246438Monitor
Meshtastic Repeated Public and Private Keypairs
CriticalCVSS 9.5Proof of conceptEPSS 1%meshtastic · meshtastic firmwareJun 19, 2025
- CVE-2025-5363732Monitor
Meshtastic allows Command Injection in GitHub Action
HighCVSS 8.0No exploitEPSS 0%meshtastic · meshtastic firmwareJul 10, 2025
- CVE-2025-5529232Monitor
In Meshtastic, an attacker can spoof licensed amateur flag for a node
HighCVSS 8.2No exploitEPSS 0%meshtastic · meshtastic firmwareJan 27, 2026
- CVE-2024-4503830Monitor
Device crash via malformed MQTT packet when downlink is enabled in Meshtastic device firmware
HighCVSS 7.5No exploitEPSS 1%meshtastic · meshtastic firmwareAug 27, 2024
- CVE-2026-4256630Monitor
Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failure
HighCVSS 7.5No exploitEPSS 0%meshtastic · meshtastic firmwareJul 19, 2026
- CVE-2024-5150030Monitor
Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmware
HighCVSS 7.5No exploitEPSS 0%meshtastic · meshtastic firmwareNov 4, 2024
- CVE-2025-2479826Monitor
Meshtastic crashes via an unimplemented routing module reply
MediumCVSS 6.5No exploitEPSS 0%meshtastic · meshtastic firmwareJul 10, 2025
- CVE-2024-4707925Monitor
Unauthorized usage of remote hardware module because of missing channel verification
MediumCVSS 6.4No exploitEPSS 0%meshtastic · meshtastic firmwareOct 7, 2024
- CVE-2025-2160821Monitor
Forged packets over MQTT can show up in direct messages in Meshtastic firmware
MediumCVSS 5.3No exploitEPSS 0%meshtastic · meshtastic firmwareFeb 18, 2025
- CVE-2025-5362721Monitor
Meshtastic firmware allows forged DMs with no PKC to show up as encrypted
MediumCVSS 5.3No exploitEPSS 0%meshtastic · meshtastic firmwareDec 29, 2025
- CVE-2024-4706510Monitor
Traceroute_APP responses are not rate-limited.
LowCVSS 2.7No exploitEPSS 0%meshtastic · meshtastic firmwareJul 11, 2025