CVE-2025-53627 affects Meshtastic firmware versions 2.5 through 2.7.14, stemming from an intentional design choice to maintain backward compatibility. The vulnerability allows an attacker with knowledge of a shared channel key to inject spoofed direct messages that appear to be end-to-end encrypted (PKI), even though they are only secured with legacy AES-256-CTR encryption. This downgrade attack undermines user expectations of security, as applications fail to differentiate between PKI and legacy encrypted messages. Rated CVSS 5.3 MEDIUM, the attack requires no user interaction and has a low impact on integrity, with no known active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.5.0, < 2.7.15CPE matchmatch criteria | cpe:2.3:o:meshtastic:meshtastic_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.