CVE-2025-24797
CVSS 3.1 Score 9.4 of 10 (high)
Details
Published Apr 15, 2025
CWE ID 119
CWE ID 122
Summary
CVE-2025-24797 is a newly identified vulnerability affecting Meshtastic, an open-source mesh networking solution. The flaw stems from a faulty processing mechanism for mesh packets containing malformed protobuf data. This defect can trigger a buffer overflow, paving the way for an attacker to hijack the execution flow and potentially execute arbitrary code without requiring authentication or user interaction. The vulnerability exists on the default channel and is fixed in Meshtastic version 2.6.2.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Meshtastic Firmware
Affected Vendors
- Meshtastic LLC