CVE-2024-47078

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Sep 25, 2024
Updated: Dec 2, 2024
CWE ID 287
CWE ID 863

Summary

CVE-2024-47078 affects the open-source mesh network project, Meshtastic. This vulnerability, which was patched in version 2.5.1, pertains to the MQTT (Message Queue Telemetry Transport) implementation. Nodes using unpatched versions were susceptible to authentication and authorization bypasses, enabling unauthorized control. The weaknesses allowed attackers to gain control of MQTT-connected nodes, either via an internet connection or proxied through Bluetooth, without proper authentication. This could lead to significant security implications in off-grid, decentralized mesh networks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Meshtastic Firmware

Affected Vendors

  • Meshtastic LLC