📦 Meshtastic Firmware

by Meshtastic

🔍 What is Meshtastic Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-55293

CRITICAL CVSS 9.4 Aug 18, 2025

This vulnerability allows an attacker to impersonate legitimate nodes in a Meshtastic mesh network by manipulating public key assignments. Attackers can first send a NodeInfo packet with an empty publ...

CVE-2025-24797

CRITICAL CVSS 9.4 Apr 15, 2025

CVE-2025-24797 is a critical buffer overflow vulnerability in Meshtastic firmware that allows unauthenticated attackers to execute arbitrary code on affected devices. The vulnerability occurs when dev...

CVE-2025-55292

HIGH CVSS 8.2 Jan 28, 2026

This vulnerability allows attackers to impersonate legitimate nodes in Meshtastic mesh networks by forging NodeInfo packets that claim HAM mode is enabled. This downgrades security by forcing other no...

CVE-2025-52464

HIGH CVSS 8.3 Jun 19, 2025

This vulnerability in Meshtastic firmware allows attackers to decrypt direct messages when they have compiled a list of compromised cryptographic keys. It affects users running Meshtastic firmware ver...

CVE-2024-47078

HIGH CVSS 8.1 Sep 25, 2024

CVE-2024-47078 is an authentication and authorization bypass vulnerability in Meshtastic's MQTT implementation that allows unauthorized control of MQTT-connected nodes. This affects all Meshtastic use...

CVE-2024-45038

HIGH CVSS 7.5 Aug 27, 2024

This CVE describes a denial-of-service vulnerability in Meshtastic device firmware's MQTT handling. Attackers can crash devices by sending malicious MQTT messages, disrupting mesh network communicatio...

CVE-2025-53627

MEDIUM CVSS 5.3 Dec 29, 2025

This CVE describes a downgrade attack vulnerability in Meshtastic firmware where direct messages can be silently decrypted using legacy symmetric encryption instead of the intended PKI encryption. Use...

CVE-2024-47065

MEDIUM CVSS 6.5 Jul 11, 2025

This vulnerability in Meshtastic allows attackers to abuse traceroute functionality to force remote nodes to continuously respond, enabling rapid collection of SNR measurements that can compromise pos...

CVE-2025-53637

MEDIUM CVSS 4.1 Jul 10, 2025

This CVE describes a command injection vulnerability in Meshtastic's GitHub Actions workflow that allows attackers to execute arbitrary code in the CI/CD pipeline. Attackers who fork the repository an...