Meshtastic Firmware

Meshtastic · 14 CVEs

CVE-2026-42566
HIGH

Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failure

Jul 19, 2026

CVE-2025-55292
HIGH

In Meshtastic, an attacker can spoof licensed amateur flag for a node

Jan 27, 2026

CVE-2025-53627
MEDIUM

Meshtastic firmware allows forged DMs with no PKC to show up as encrypted

Dec 29, 2025

CVE-2025-55293
CRITICAL

Meshtastic allows crafting of specific NodeInfo packets that overwrite any publicKey saved in the NodeDB

Aug 18, 2025

CVE-2024-47065
LOW

Traceroute_APP responses are not rate-limited.

Jul 11, 2025

CVE-2025-53637
HIGH

Meshtastic allows Command Injection in GitHub Action

Jul 10, 2025

CVE-2025-24798
MEDIUM

Meshtastic crashes via an unimplemented routing module reply

Jul 10, 2025

CVE-2025-52464
CRITICAL

Meshtastic Repeated Public and Private Keypairs

Jun 19, 2025

CVE-2025-24797
CRITICAL

Meshtastic incorrectly hands malformed packets leads to controlled buffer overflow

Apr 14, 2025

CVE-2025-21608
MEDIUM

Forged packets over MQTT can show up in direct messages in Meshtastic firmware

Feb 18, 2025

CVE-2024-51500
HIGH

Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmwa…

Nov 4, 2024

CVE-2024-47079
MEDIUM

Unauthorized usage of remote hardware module because of missing channel verification

Oct 7, 2024

CVE-2024-47078
CRITICAL

Meshtastic firmware Authentication/Authorization Bypass via MQTT

Sep 25, 2024

CVE-2024-45038
HIGH

Device crash via malformed MQTT packet when downlink is enabled in Meshtastic device firmware

Aug 27, 2024

Showing 1 to 14 of 14 CVEs