PT-2024-31388 · Unknown · Meshtastic

Brloomis

·

Published

2024-08-27

·

Updated

2025-10-21

·

CVE-2024-45038

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Meshtastic device firmware versions prior to 2.4.1
Description The Meshtastic device firmware is subject to a denial of service vulnerability in MQTT handling. This issue is fixed in version 2.4.1 of the Meshtastic firmware and on the Meshtastic public MQTT Broker. It is strongly suggested that all users of Meshtastic, particularly those that connect to a privately hosted MQTT server, update to this or a more recent stable version right away. There are no known workarounds for this vulnerability.
Recommendations For Meshtastic device firmware versions prior to 2.4.1, update to version 2.4.1 or a more recent stable version immediately. As a temporary workaround, consider disabling MQTT handling until a patch is available. Restrict access to the Meshtastic public MQTT Broker to minimize the risk of exploitation. Avoid using the Meshtastic device firmware with privately hosted MQTT servers until the issue is resolved.

Exploit

Fix

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2024-45038
GHSA-3X3R-VW9F-PXQ5

Affected Products

Meshtastic