Out-of-Bounds Affecting meshtastic/firmware package, versions [,2.6.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.34% (57th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-MESHTASTICFIRMWARE-10292123
  • published2 Jun 2025
  • disclosed14 Apr 2025
  • creditAlain Siegrist, Marc Siegrist

Introduced: 14 Apr 2025

CVE-2025-24797  (opens in a new tab)
CWE-119  (opens in a new tab)

How to fix?

Upgrade meshtastic/firmware to version 2.6.2 or higher.

Overview

Affected versions of this package are vulnerable to Out-of-Bounds through the handling of mesh packets containing invalid protobuf data. An attacker can hijack execution flow and potentially execute arbitrary code by sending malformed packets to the target device.

Note:

This is only exploitable if the target device rebroadcasts packets on the default channel.

References

CVSS Base Scores

version 4.0
version 3.1