PT-2025-26221 · Unknown · Meshtastic

Jp-Bennett

·

Published

2025-06-04

·

Updated

2026-02-19

·

CVE-2025-52464

CVSS v2.0

9.7

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions Meshtastic versions 2.5.0 through 2.6.10
Description Meshtastic is an open source mesh networking solution. The flashing procedure of several hardware vendors was resulting in duplicated public/private keys. Additionally, Meshtastic was failing to properly initialize the internal randomness pool on some platforms, leading to possible low-entropy key generation. When users with an affected key pair sent Direct Messages, those messages could be captured and decrypted by an attacker that has compiled the list of compromised keys.
Recommendations For versions 2.5.0 through 2.6.10, update to version 2.6.11 or later, where key generation is delayed until the first time the LoRa region is set, along with warning users when a compromised key is detected. As a temporary workaround for versions 2.5.0 through 2.6.10, consider doing a complete device wipe to remove vendor-cloned keys.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-07447
CVE-2025-52464
GHSA-GQ7V-JR8C-MFR7

Affected Products

Meshtastic