PT-2026-61517 · Unknown · Meshtastic

CVE-2026-42566

·

Published

2026-07-19

·

Updated

2026-07-20

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Meshtastic versions prior to 2.7.23.b246bcd
Description A node advertising a User.long name with malformed character encoding can cause other radios to become unusable over BLE when managed via the iOS app. This occurs because a null terminator may be placed in the middle of a multibyte sequence, creating a poisoned entry in the node database. The iOS app enforces encoding validation and fails to parse the database when such an entry is present, causing the BLE sync to enter a fail/retry loop and resulting in a loss of control over the device. This issue can propagate through the mesh, affecting iOS users across a wide geographical area. The malformed name can occur naturally through ordinary buffer truncation and does not necessarily require malicious crafting.
Recommendations Update to version 2.7.23.b246bcd or later. As a temporary workaround, use the Python CLI to manually identify and remove offending entries from the node database.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42566

Affected Products

Meshtastic