PT-2025-6926 · Unknown · Meshtastic
Komelt
·
Published
2025-02-18
·
Updated
2025-02-18
·
CVE-2025-21608
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Meshtastic versions prior to 2.5.19
Description:
Meshtastic is an open source mesh networking solution. In affected firmware versions, crafted packets over MQTT can appear as a DM in client to a node even though they were not decoded with PKC.
Recommendations:
For versions prior to 2.5.19, upgrade to version 2.5.19 to resolve the issue.
As a temporary workaround, consider restricting the use of MQTT protocol until a patch is available.
Avoid using the
PKC decoding for DM packets in the affected firmware versions until the issue is resolved.Exploit
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Meshtastic