CRITICAL🇵🇱 Wersja polska

CVE-2025-55293

CVSS 9.4v3.1pub. 2025-08-18upd. 2025-10-17

Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publicKey first, then overwrite it with a new key. First sending a empty key bypasses 'if (p.public_key.size > 0) {', clearing the existing publicKey (and resetting the size to 0) for a known node. Then a new key bypasses 'if (info->user.public_key.size > 0) {', and this malicious key is stored in NodeDB. This vulnerability is fixed in 2.6.3.

🤖 AI Analysis
How it works

The vulnerability results from flawed validation logic of the public key size during NodeInfo packet processing. In the first step, an attacker sends a NodeInfo packet with an empty publicKey field — the key size check condition ('if (p.public_key.size > 0)') evaluates to false, causing the existing public key for that node to be cleared and its size reset to 0. Next, the attacker sends another NodeInfo packet containing a new malicious public key — since the size of the previously stored key is now 0, the second validation condition ('if (info->user.public_key.size > 0)') is also bypassed, and the malicious key is persisted in the NodeDB. As a result, the attacker can impersonate any known node in the network.

Impact

An attacker can permanently overwrite the public key of a selected node in the Meshtastic network with their own key, enabling identity takeover of that node, decryption of communication directed to it, and man-in-the-middle attacks within the entire mesh network.

Mitigation & patch

Meshtastic Firmware must be updated to version 2.6.3 or later, where the vulnerability has been fixed. The patch is available in the vendor's repository (commit cf7f0f9d0895602df3453a4f5cfea843f4e09744).

Who is affected

Meshtastic Firmware in all versions before 2.6.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
  • Meshtastic Firmware

    OS
    Meshtastic
    < 2.6.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-52464CRITICAL9.5PL ✓same product

Meshtastic Firmware: słaba entropia i duplikacja kluczy kryptograficznych

CVE-2025-24797CRITICAL9.4PL ✓same product

RCE przez buffer overflow w obsłudze pakietów protobuf w Meshtastic Firmware

CVE-2026-42566HIGH7.5PL ✓same product

Meshtastic: nieprawidłowe kodowanie nazwy węzła powoduje DoS przez BLE

CVE-2025-55292HIGH8.2same product

Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is ident...

CVE-2024-47078HIGH8.1same product

Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over ...