PT-2024-31388 · Unknown · Meshtastic
Brloomis
·
Published
2024-08-27
·
Updated
2025-10-21
·
CVE-2024-45038
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Meshtastic device firmware versions prior to 2.4.1
Description
The Meshtastic device firmware is subject to a denial of service vulnerability in MQTT handling. This issue is fixed in version 2.4.1 of the Meshtastic firmware and on the Meshtastic public MQTT Broker. It is strongly suggested that all users of Meshtastic, particularly those that connect to a privately hosted MQTT server, update to this or a more recent stable version right away. There are no known workarounds for this vulnerability.
Recommendations
For Meshtastic device firmware versions prior to 2.4.1, update to version 2.4.1 or a more recent stable version immediately.
As a temporary workaround, consider disabling MQTT handling until a patch is available.
Restrict access to the Meshtastic public MQTT Broker to minimize the risk of exploitation.
Avoid using the Meshtastic device firmware with privately hosted MQTT servers until the issue is resolved.
Exploit
Fix
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Meshtastic