CVE-2025-24798: Meshtastic Firmware
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Meshtastic is an open source mesh networking solution. From 1.2.1 until 2.6.2, a packet sent to the routing module that contains want_response==true causes a crash. This can lead to a degradation of service for nodes within range of a malicious sender, or via MQTT if downlink is enabled. This vulnerability is fixed in 2.6.2.
Affected products
- Meshtastic Meshtastic Firmware: from 1.2.1, before 2.6.2 (fixed in 2.6.2)
Published 2025-07-10. Last modified 2026-06-17.