PT-2025-6926 · Unknown · Meshtastic

Komelt

·

Published

2025-02-18

·

Updated

2025-02-18

·

CVE-2025-21608

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Meshtastic versions prior to 2.5.19
Description: Meshtastic is an open source mesh networking solution. In affected firmware versions, crafted packets over MQTT can appear as a DM in client to a node even though they were not decoded with PKC.
Recommendations: For versions prior to 2.5.19, upgrade to version 2.5.19 to resolve the issue. As a temporary workaround, consider restricting the use of MQTT protocol until a patch is available. Avoid using the PKC decoding for DM packets in the affected firmware versions until the issue is resolved.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2025-21608
GHSA-C967-QC39-3HF5

Affected Products

Meshtastic