CVE-2024-47078
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-47078 affects the open-source mesh network project, Meshtastic. This vulnerability, which was patched in version 2.5.1, pertains to the MQTT (Message Queue Telemetry Transport) implementation. Nodes using unpatched versions were susceptible to authentication and authorization bypasses, enabling unauthorized control. The weaknesses allowed attackers to gain control of MQTT-connected nodes, either via an internet connection or proxied through Bluetooth, without proper authentication. This could lead to significant security implications in off-grid, decentralized mesh networks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Meshtastic Firmware
Affected Vendors
- Meshtastic LLC