CVE-2025-24797

CVSS 3.1 Score 9.4 of 10 (high)

Details

Published Apr 15, 2025
CWE ID 119
CWE ID 122

Summary

CVE-2025-24797 is a newly identified vulnerability affecting Meshtastic, an open-source mesh networking solution. The flaw stems from a faulty processing mechanism for mesh packets containing malformed protobuf data. This defect can trigger a buffer overflow, paving the way for an attacker to hijack the execution flow and potentially execute arbitrary code without requiring authentication or user interaction. The vulnerability exists on the default channel and is fixed in Meshtastic version 2.6.2.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Meshtastic Firmware

Affected Vendors

  • Meshtastic LLC