Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Meshtastic

First CVE: Aug 27, 2024Active for: 2 yearsTotal CVEs: 13
35.4
VTI Score
Medium

Meshtastic develops firmware for open-source mesh-networking radio devices intended for off-grid and resilient communication, a niche but growing embedded platform. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including improper authentication, resource-exposure flaws, heap-based buffer overflows, and exception-handling gaps that reflect the constraints of embedded wireless systems and the security-sensitive nature of communication infrastructure. Defenders deploying Meshtastic devices should prioritize firmware updates and restrict device access to trusted networks; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
4.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Meshtastic over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 27, 2024
22 months ago
Most Recent CVE
Jan 28, 2026
177 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-55293CRITICAL
Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publicKey first, then overwrite it with a new key. First sending
Aug 18, 20259.832NONO
CVE-2025-24797CRITICAL
Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protobuf data can result in an attacker-controlled buffer overflow
Apr 15, 20259.830NONO
CVE-2025-55292HIGH
Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by their NodeID, generated from the MAC address, rather than the
Jan 28, 20268.226NONO
CVE-2025-52464HIGH
Meshtastic is an open source mesh networking solution. In versions from 2.5.0 to before 2.6.11, the flashing procedure of several hardware vendors was resulting in duplicated publi
Jun 19, 20258.326NONO
CVE-2024-47078CRITICAL
Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. Nodes can c
Sep 25, 20249.826NONO
CVE-2025-53637HIGH
Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_request_target event, which has extensive permissions, and can be
Jul 10, 20258.022NONO
CVE-2024-51500HIGH
Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets claiming to be from the special broadcast address (0xFFFFFFF
Nov 4, 20247.522NONO
CVE-2024-45038HIGH
Meshtastic device firmware is a firmware for meshtastic devices to run an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Meshtast
Aug 27, 20247.522NONO
CVE-2025-53627MEDIUM
Meshtastic is an open source mesh networking solution. The Meshtastic firmware (starting from version 2.5) introduces asymmetric encryption (PKI) for direct messages, but when the
Dec 29, 20255.320NONO
CVE-2024-47065MEDIUM
Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not rate limited. Given that there are SNR measurements attribu
Jul 11, 20256.519NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
38%
38%
23%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (84.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (15.4%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None12 (92.3%)
Unknown0 (0.0%)
Required1 (7.7%)
Privileges Required
Low2 (15.4%)
High0 (0.0%)
None11 (84.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Meshtastic.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Meshtastic — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Meshtastic's Products

View all 1 CNAs →

Top CWEs