CRITICAL🇵🇱 Wersja polska

CVE-2025-24797

CVSS 9.4v3.1pub. 2025-04-15upd. 2025-10-03

Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protobuf data can result in an attacker-controlled buffer overflow, allowing an attacker to hijack execution flow, potentially resulting in remote code execution. This attack does not require authentication or user interaction, as long as the target device rebroadcasts packets on the default channel. This vulnerability fixed in 2.6.2.

🤖 AI Analysis
How it works

An attacker sends a specially crafted mesh packet containing malformed data in protobuf format. An error in parsing such data leads to a buffer overflow on the heap, which the attacker controls. This makes it possible to overwrite critical memory structures and take over the application's execution flow. The attack is possible as long as the target device retransmits packets on the default mesh network channel.

Impact

An attacker can remotely execute arbitrary code on the victim's device (RCE) and gain unauthorized access to data or disrupt device operation, which corresponds to a high impact on system confidentiality and availability.

Mitigation & patch

Meshtastic Firmware should be updated to version 2.6.2 or later, in which the vulnerability has been fixed. Details are available in the manufacturer's references: https://github.com/meshtastic/firmware/security/advisories/GHSA-33hw-xhfh-944r

Who is affected

Meshtastic Firmware in versions prior to 2.6.2, running on devices that retransmit packets on the default mesh network channel.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
  • Meshtastic Firmware

    OS
    Meshtastic
    < 2.6.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2025-55293CRITICAL9.4PL ✓same product

Meshtastic Firmware: pominięcie uwierzytelnienia przez podmianę klucza publicznego

CVE-2025-52464CRITICAL9.5PL ✓same product

Meshtastic Firmware: słaba entropia i duplikacja kluczy kryptograficznych

CVE-2026-42566HIGH7.5PL ✓same product

Meshtastic: nieprawidłowe kodowanie nazwy węzła powoduje DoS przez BLE

CVE-2025-55292HIGH8.2same product

Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is ident...

CVE-2024-47078HIGH8.1same product

Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over ...