PT-2025-16280 · Unknown · Meshtastic

Alainx277

+1

·

Published

2025-04-11

·

Updated

2025-10-03

·

CVE-2025-24797

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Meshtastic versions prior to 2.6.2
Description Meshtastic is an open source mesh networking solution. A flaw in processing mesh packets with invalid protobuf data can lead to an attacker-controlled buffer overflow, potentially allowing an attacker to hijack execution flow and achieve remote code execution. This attack does not require authentication or user interaction, provided the target device rebroadcasts packets on the default channel.
Recommendations Update to version 2.6.2 to address the issue.

Exploit

Fix

RCE

Heap Based Buffer Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-04856
CVE-2025-24797
GHSA-33HW-XHFH-944R

Affected Products

Meshtastic