Vulnerability Description
Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protobuf data can result in an attacker-controlled buffer overflow, allowing an attacker to hijack execution flow, potentially resulting in remote code execution. This attack does not require authentication or user interaction, as long as the target device rebroadcasts packets on the default channel. This vulnerability fixed in 2.6.2.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Meshtastic | Meshtastic Firmware | < 2.6.2 |
Related Weaknesses (CWE)
References
- https://github.com/meshtastic/firmware/security/advisories/GHSA-33hw-xhfh-944rThird Party Advisory
FAQ
What is CVE-2025-24797?
CVE-2025-24797 is a vulnerability with a CVSS score of 9.4 (CRITICAL). Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protobuf data can result in an attacker-controlled buffer overflow, allowing an attack...
How severe is CVE-2025-24797?
CVE-2025-24797 has been rated CRITICAL with a CVSS base score of 9.4/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-24797?
Check the references section above for vendor advisories and patch information. Affected products include: Meshtastic Meshtastic Firmware.