Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-21075 | Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_request_target event, which has extensive permissions, and can be initiated by an attacker who forked the repository and created a pull request. In the shell code execution part, user-controlled input is interpolated unsafely into the code. If this were to be exploited, attackers could inject unauthorized code into the repository. This vulnerability is fixed in 2.6.6. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 22 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Meshtastic meshtastic Firmware
|
|
CPEs | cpe:2.3:o:meshtastic:meshtastic_firmware:*:*:*:*:*:*:*:* | |
Vendors & Products |
Meshtastic meshtastic Firmware
|
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-11T16:50:38.545Z
Reserved: 2025-07-07T14:20:38.390Z
Link: CVE-2025-53637

Updated: 2025-07-11T16:50:35.293Z

Status : Analyzed
Published: 2025-07-10T22:15:24.580
Modified: 2025-08-22T16:02:16.093
Link: CVE-2025-53637

No data.

Updated: 2025-07-13T21:07:41Z