CVE-2024-29862: Chirpstack Gateway Bridge
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4.2.1 and chirpstack-gateway-bridge before 4.0.11 wrongly accepts certain TCP packets when a connection is not in the ESTABLISHED state.
Affected products
- Chirpstack Gateway Bridge: before 4.0.11 (fixed in 4.0.11)
- Chirpstack Mqtt Forwarder: before 4.2.1 (fixed in 4.2.1)
Published 2024-03-21. Last modified 2026-06-17.