Meshtastic Firmware
Vendor:
First CVE: Aug 27, 2024 · Active for 1 year
13
Total CVEs
More Total CVEs than 91% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Meshtastic Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 27, 2024
22 months ago
Most Recent CVE
Jan 28, 2026
180 days ago
CVE Severity & Scoring
Meshtastic Firmware13 CVEs
38%
38%
23%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (84.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (15.4%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None12 (92.3%)
Unknown0 (0.0%)
Required1 (7.7%)
Privileges Required
Low2 (15.4%)
High0 (0.0%)
None11 (84.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55293CRITICAL Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publicKey first, then overwrite it with a new key. First sending | Aug 18, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-24797CRITICAL Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protobuf data can result in an attacker-controlled buffer overflow | Apr 15, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-55292HIGH Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by their NodeID, generated from the MAC address, rather than the | Jan 28, 2026 | 8.2 | 26 | NO | NO |
CVE-2025-52464HIGH Meshtastic is an open source mesh networking solution. In versions from 2.5.0 to before 2.6.11, the flashing procedure of several hardware vendors was resulting in duplicated publi | Jun 19, 2025 | 8.3 | 26 | NO | NO |
CVE-2024-47078CRITICAL Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. Nodes can c | Sep 25, 2024 | 9.8 | 26 | NO | NO |
CVE-2025-53637HIGH Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_request_target event, which has extensive permissions, and can be | Jul 10, 2025 | 8.0 | 22 | NO | NO |
CVE-2024-51500HIGH Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets claiming to be from the special broadcast address (0xFFFFFFF | Nov 4, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-45038HIGH Meshtastic device firmware is a firmware for meshtastic devices to run an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Meshtast | Aug 27, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-53627MEDIUM Meshtastic is an open source mesh networking solution. The Meshtastic firmware (starting from version 2.5) introduces asymmetric encryption (PKI) for direct messages, but when the | Dec 29, 2025 | 5.3 | 20 | NO | NO |
CVE-2024-47065MEDIUM Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not rate limited. Given that there are SNR measurements attribu | Jul 11, 2025 | 6.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Meshtastic Firmware
Top CWEs
Versions
No cataloged versions.