Записи meshtastic
14 опубликованных записей вендора meshtastic.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 57,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-287 Improper Authentication2
- CWE-1287 Improper Validation of Specified Type of Input1
- CWE-138 Improper Neutralization of Special Elements1
- CWE-20 Improper Input Validation1
- CWE-331 Insufficient Entropy1
- CWE-345 Insufficient Verification of Data Authenticity1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2025-24797Proof of concept | Meshtastic incorrectly hands malformed packets leads to controlled buffer overflowmeshtastic · meshtastic firmware · CWE-119 | Критическая9,8 | — | 0,9 % | 14 апр. 2025 г. |
39Наблюдать | CVE-2024-47078Эксплойта нет | Meshtastic firmware Authentication/Authorization Bypass via MQTTmeshtastic · meshtastic firmware · CWE-287 | Критическая9,8 | — | 0,5 % | 25 сент. 2024 г. |
39Наблюдать | CVE-2025-55293Эксплойта нет | Meshtastic allows crafting of specific NodeInfo packets that overwrite any publicKey saved in the NodeDBmeshtastic · meshtastic firmware · CWE-287 | Критическая9,8 | — | 0,4 % | 18 авг. 2025 г. |
38Наблюдать | CVE-2025-52464Proof of concept | Meshtastic Repeated Public and Private Keypairsmeshtastic · meshtastic firmware · CWE-331 | Критическая9,5 | — | 0,6 % | 19 июн. 2025 г. |
32Наблюдать | CVE-2025-53637Эксплойта нет | Meshtastic allows Command Injection in GitHub Actionmeshtastic · meshtastic firmware · CWE-78 | Высокая8,0 | — | 0,3 % | 10 июл. 2025 г. |
32Наблюдать | CVE-2025-55292Эксплойта нет | In Meshtastic, an attacker can spoof licensed amateur flag for a nodemeshtastic · meshtastic firmware · CWE-348 | Высокая8,2 | — | 0,1 % | 27 янв. 2026 г. |
30Наблюдать | CVE-2024-45038Эксплойта нет | Device crash via malformed MQTT packet when downlink is enabled in Meshtastic device firmwaremeshtastic · meshtastic firmware · CWE-755 | Высокая7,5 | — | 0,6 % | 27 авг. 2024 г. |
30Наблюдать | CVE-2026-42566Эксплойта нет | Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failuremeshtastic · meshtastic firmware · CWE-20 | Высокая7,5 | — | 0,5 % | 19 июл. 2026 г. |
30Наблюдать | CVE-2024-51500Эксплойта нет | Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmwaremeshtastic · meshtastic firmware · CWE-138 | Высокая7,5 | — | 0,4 % | 4 нояб. 2024 г. |
26Наблюдать | CVE-2025-24798Эксплойта нет | Meshtastic crashes via an unimplemented routing module replymeshtastic · meshtastic firmware · CWE-617 | Средняя6,5 | — | 0,4 % | 10 июл. 2025 г. |
25Наблюдать | CVE-2024-47079Эксплойта нет | Unauthorized usage of remote hardware module because of missing channel verificationmeshtastic · meshtastic firmware · CWE-345 | Средняя6,4 | — | 0,2 % | 7 окт. 2024 г. |
21Наблюдать | CVE-2025-21608Эксплойта нет | Forged packets over MQTT can show up in direct messages in Meshtastic firmwaremeshtastic · meshtastic firmware · CWE-668 | Средняя5,3 | — | 0,4 % | 18 февр. 2025 г. |
21Наблюдать | CVE-2025-53627Эксплойта нет | Meshtastic firmware allows forged DMs with no PKC to show up as encryptedmeshtastic · meshtastic firmware · CWE-1287 | Средняя5,3 | — | 0,2 % | 29 дек. 2025 г. |
10Наблюдать | CVE-2024-47065Эксплойта нет | Traceroute_APP responses are not rate-limited.meshtastic · meshtastic firmware · CWE-799 | Низкая2,7 | — | 0,2 % | 11 июл. 2025 г. |
- CVE-2025-2479739Наблюдать
Meshtastic incorrectly hands malformed packets leads to controlled buffer overflow
КритическаяCVSS 9,8Proof of conceptEPSS 1 %meshtastic · meshtastic firmware14 апр. 2025 г.
- CVE-2024-4707839Наблюдать
Meshtastic firmware Authentication/Authorization Bypass via MQTT
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %meshtastic · meshtastic firmware25 сент. 2024 г.
- CVE-2025-5529339Наблюдать
Meshtastic allows crafting of specific NodeInfo packets that overwrite any publicKey saved in the NodeDB
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %meshtastic · meshtastic firmware18 авг. 2025 г.
- CVE-2025-5246438Наблюдать
Meshtastic Repeated Public and Private Keypairs
КритическаяCVSS 9,5Proof of conceptEPSS 1 %meshtastic · meshtastic firmware19 июн. 2025 г.
- CVE-2025-5363732Наблюдать
Meshtastic allows Command Injection in GitHub Action
ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %meshtastic · meshtastic firmware10 июл. 2025 г.
- CVE-2025-5529232Наблюдать
In Meshtastic, an attacker can spoof licensed amateur flag for a node
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %meshtastic · meshtastic firmware27 янв. 2026 г.
- CVE-2024-4503830Наблюдать
Device crash via malformed MQTT packet when downlink is enabled in Meshtastic device firmware
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %meshtastic · meshtastic firmware27 авг. 2024 г.
- CVE-2026-4256630Наблюдать
Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failure
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %meshtastic · meshtastic firmware19 июл. 2026 г.
- CVE-2024-5150030Наблюдать
Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmware
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %meshtastic · meshtastic firmware4 нояб. 2024 г.
- CVE-2025-2479826Наблюдать
Meshtastic crashes via an unimplemented routing module reply
СредняяCVSS 6,5Эксплойта нетEPSS 0 %meshtastic · meshtastic firmware10 июл. 2025 г.
- CVE-2024-4707925Наблюдать
Unauthorized usage of remote hardware module because of missing channel verification
СредняяCVSS 6,4Эксплойта нетEPSS 0 %meshtastic · meshtastic firmware7 окт. 2024 г.
- CVE-2025-2160821Наблюдать
Forged packets over MQTT can show up in direct messages in Meshtastic firmware
СредняяCVSS 5,3Эксплойта нетEPSS 0 %meshtastic · meshtastic firmware18 февр. 2025 г.
- CVE-2025-5362721Наблюдать
Meshtastic firmware allows forged DMs with no PKC to show up as encrypted
СредняяCVSS 5,3Эксплойта нетEPSS 0 %meshtastic · meshtastic firmware29 дек. 2025 г.
- CVE-2024-4706510Наблюдать
Traceroute_APP responses are not rate-limited.
НизкаяCVSS 2,7Эксплойта нетEPSS 0 %meshtastic · meshtastic firmware11 июл. 2025 г.