CVE-2024-29862: Chirpstack Gateway Bridge

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4.2.1 and chirpstack-gateway-bridge before 4.0.11 wrongly accepts certain TCP packets when a connection is not in the ESTABLISHED state.

Affected products

  • Chirpstack Gateway Bridge: before 4.0.11 (fixed in 4.0.11)
  • Chirpstack Mqtt Forwarder: before 4.2.1 (fixed in 4.2.1)

Published 2024-03-21. Last modified 2026-06-17.