PT-2026-61517 · Unknown · Meshtastic
CVE-2026-42566
·
Published
2026-07-19
·
Updated
2026-07-20
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Meshtastic versions prior to 2.7.23.b246bcd
Description
A node advertising a
User.long name with malformed character encoding can cause other radios to become unusable over BLE when managed via the iOS app. This occurs because a null terminator may be placed in the middle of a multibyte sequence, creating a poisoned entry in the node database. The iOS app enforces encoding validation and fails to parse the database when such an entry is present, causing the BLE sync to enter a fail/retry loop and resulting in a loss of control over the device. This issue can propagate through the mesh, affecting iOS users across a wide geographical area. The malformed name can occur naturally through ordinary buffer truncation and does not necessarily require malicious crafting.Recommendations
Update to version 2.7.23.b246bcd or later.
As a temporary workaround, use the Python CLI to manually identify and remove offending entries from the node database.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Meshtastic