Description
Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able to appear as a DM in client to a node even though they were not decoded with PKC. This issue has been addressed in version 2.5.19 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Published: 2025-02-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5098 Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able to appear as a DM in client to a node even though they were not decoded with PKC. This issue has been addressed in version 2.5.19 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Tue, 23 Sep 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Meshtastic meshtastic Firmware
CPEs cpe:2.3:o:meshtastic:meshtastic_firmware:*:*:*:*:*:*:*:*
Vendors & Products Meshtastic meshtastic Firmware
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 19 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Feb 2025 18:30:00 +0000

Type Values Removed Values Added
Description Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able to appear as a DM in client to a node even though they were not decoded with PKC. This issue has been addressed in version 2.5.19 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Title Forged packets over MQTT can show up in direct messages in Meshtastic firmware
Weaknesses CWE-668
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Meshtastic Firmware Meshtastic Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-19T15:16:07.151Z

Reserved: 2024-12-29T03:00:24.712Z

Link: CVE-2025-21608

cve-icon Vulnrichment

Updated: 2025-02-19T14:44:15.425Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-18T19:15:25.220

Modified: 2025-09-23T19:20:35.733

Link: CVE-2025-21608

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T15:26:21Z

Weaknesses