Meshtastic develops firmware for open-source mesh-networking radio devices intended for off-grid and resilient communication, a niche but growing embedded platform. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including improper authentication, resource-exposure flaws, heap-based buffer overflows, and exception-handling gaps that reflect the constraints of embedded wireless systems and the security-sensitive nature of communication infrastructure. Defenders deploying Meshtastic devices should prioritize firmware updates and restrict device access to trusted networks; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Meshtastic over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55293CRITICAL Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publicKey first, then overwrite it with a new key. First sending | Aug 18, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-24797CRITICAL Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protobuf data can result in an attacker-controlled buffer overflow | Apr 15, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-55292HIGH Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by their NodeID, generated from the MAC address, rather than the | Jan 28, 2026 | 8.2 | 26 | NO | NO |
CVE-2025-52464HIGH Meshtastic is an open source mesh networking solution. In versions from 2.5.0 to before 2.6.11, the flashing procedure of several hardware vendors was resulting in duplicated publi | Jun 19, 2025 | 8.3 | 26 | NO | NO |
CVE-2024-47078CRITICAL Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. Nodes can c | Sep 25, 2024 | 9.8 | 26 | NO | NO |
CVE-2025-53637HIGH Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_request_target event, which has extensive permissions, and can be | Jul 10, 2025 | 8.0 | 22 | NO | NO |
CVE-2024-51500HIGH Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets claiming to be from the special broadcast address (0xFFFFFFF | Nov 4, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-45038HIGH Meshtastic device firmware is a firmware for meshtastic devices to run an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Meshtast | Aug 27, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-53627MEDIUM Meshtastic is an open source mesh networking solution. The Meshtastic firmware (starting from version 2.5) introduces asymmetric encryption (PKI) for direct messages, but when the | Dec 29, 2025 | 5.3 | 20 | NO | NO |
CVE-2024-47065MEDIUM Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not rate limited. Given that there are SNR measurements attribu | Jul 11, 2025 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Meshtastic.
Media articles that mention a CVE ID that affects a product developed by Meshtastic — matched by CVE ID, not by vendor name.