Meshtastic Firmware
Meshtastic · 14 CVEs
Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failure
Jul 19, 2026
In Meshtastic, an attacker can spoof licensed amateur flag for a node
Jan 27, 2026
Meshtastic firmware allows forged DMs with no PKC to show up as encrypted
Dec 29, 2025
Meshtastic allows crafting of specific NodeInfo packets that overwrite any publicKey saved in the NodeDB
Aug 18, 2025
Traceroute_APP responses are not rate-limited.
Jul 11, 2025
Meshtastic allows Command Injection in GitHub Action
Jul 10, 2025
Meshtastic crashes via an unimplemented routing module reply
Jul 10, 2025
Meshtastic Repeated Public and Private Keypairs
Jun 19, 2025
Meshtastic incorrectly hands malformed packets leads to controlled buffer overflow
Apr 14, 2025
Forged packets over MQTT can show up in direct messages in Meshtastic firmware
Feb 18, 2025
Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmwa…
Nov 4, 2024
Unauthorized usage of remote hardware module because of missing channel verification
Oct 7, 2024
Meshtastic firmware Authentication/Authorization Bypass via MQTT
Sep 25, 2024
Device crash via malformed MQTT packet when downlink is enabled in Meshtastic device firmware
Aug 27, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-42566 | Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failure | HIGH | 0.49% | Jul 19, 2026 |
| CVE-2025-55292 | In Meshtastic, an attacker can spoof licensed amateur flag for a node | HIGH | 0.15% | Jan 27, 2026 |
| CVE-2025-53627 | Meshtastic firmware allows forged DMs with no PKC to show up as encrypted | MEDIUM | 0.20% | Dec 29, 2025 |
| CVE-2025-55293 | Meshtastic allows crafting of specific NodeInfo packets that overwrite any publicKey saved in the NodeDB | CRITICAL | 0.44% | Aug 18, 2025 |
| CVE-2024-47065 | Traceroute_APP responses are not rate-limited. | LOW | 0.26% | Jul 11, 2025 |
| CVE-2025-53637 | Meshtastic allows Command Injection in GitHub Action | HIGH | 0.36% | Jul 10, 2025 |
| CVE-2025-24798 | Meshtastic crashes via an unimplemented routing module reply | MEDIUM | 0.41% | Jul 10, 2025 |
| CVE-2025-52464 | Meshtastic Repeated Public and Private Keypairs | CRITICAL | 0.58% | Jun 19, 2025 |
| CVE-2025-24797 | Meshtastic incorrectly hands malformed packets leads to controlled buffer overflow | CRITICAL | 0.88% | Apr 14, 2025 |
| CVE-2025-21608 | Forged packets over MQTT can show up in direct messages in Meshtastic firmware | MEDIUM | 0.37% | Feb 18, 2025 |
| CVE-2024-51500 | Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmware | HIGH | 0.42% | Nov 4, 2024 |
| CVE-2024-47079 | Unauthorized usage of remote hardware module because of missing channel verification | MEDIUM | 0.19% | Oct 7, 2024 |
| CVE-2024-47078 | Meshtastic firmware Authentication/Authorization Bypass via MQTT | CRITICAL | 0.46% | Sep 25, 2024 |
| CVE-2024-45038 | Device crash via malformed MQTT packet when downlink is enabled in Meshtastic device firmware | HIGH | 0.60% | Aug 27, 2024 |
Showing 1 to 14 of 14 CVEs