CVE-2025-24798
MEDIUMmeshtastic_firmware 1.2.1-2.6.2 - Denial of Service via Routing Module want_response Packet
Title source: llmDescription
Meshtastic is an open source mesh networking solution. From 1.2.1 until 2.6.2, a packet sent to the routing module that contains want_response==true causes a crash. This can lead to a degradation of service for nodes within range of a malicious sender, or via MQTT if downlink is enabled. This vulnerability is fixed in 2.6.2.
References (3)
Core 3
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://github.com/meshtastic/firmware/security/advisories/GHSA-4q84-546j-3mf5
Patch x_refsource_misc
https://github.com/meshtastic/firmware/commit/dc100e4d3e3dfbf58d3ead8141a49cddb0cbdc19
Scores
CVSS v3
4.3
EPSS
0.0037
EPSS Percentile
29.0%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-617
Status
published
Products (1)
meshtastic/meshtastic_firmware
1.2.1 - 2.6.2
Published
Jul 10, 2025
Tracked Since
Feb 18, 2026