Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

firmware — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in firmware, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting firmware, categorized by the specific weakness type and associated tags. It collects a comprehensive history of reported issues, covering a defined time range of documented flaws and their respective remediation advisories from various vendors. Readers can use this aggregation to track a vendor’s published security updates, analyze the prevalence of a particular weakness class, and review the historical vulnerability pattern for a specific product line. The entries are organized to facilitate cross-referencing between individual incidents, allowing for a structured review of how firmware defects have evolved and been addressed over time. No specific CVE identifiers are listed in this introductory overview; instead, the focus remains on the broader collection of weaknesses and their contextual impact on firmware security.

Vendor: meshtastic

CVE ID Title CVSS Severity Published
CVE-2026-42566 Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failure CWE-20 7.5 High 2026-07-19
CVE-2026-44359 Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow CWE-94 10.0 Critical 2026-07-19
CVE-2026-11405 Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface - - 2026-07-06
CVE-2026-7415 Open MQTT orchestration without read/write ACLs in Yarbo robot firmware CWE-306 9.8 Critical 2026-05-07
CVE-2026-7414 Hardcoded credentials in Yarbo robot firmware CWE-798 9.8 Critical 2026-05-07
CVE-2026-7413 Persistent undocumented backdoor access in Yarbo robot CWE-912 7.2 High 2026-05-07
CVE-2025-55292 In Meshtastic, an attacker can spoof licensed amateur flag for a node CWE-348 8.2 High 2026-01-27
CVE-2025-53627 Meshtastic firmware allows forged DMs with no PKC to show up as encrypted CWE-1287 5.3 Medium 2025-12-29
CVE-2025-55293 Meshtastic allows crafting of specific NodeInfo packets that overwrite any publicKey saved in the NodeDB CWE-287 9.4 Critical 2025-08-18
CVE-2024-47065 Traceroute_APP responses are not rate-limited. CWE-799 5.3AI Medium AI 2025-07-11
CVE-2025-53637 Meshtastic allows Command Injection in GitHub Action CWE-78 4.1 Medium 2025-07-10
CVE-2025-24798 Meshtastic crashes via an unimplemented routing module reply CWE-617 4.3 Medium 2025-07-10
CVE-2025-52464 Meshtastic Repeated Public and Private Keypairs CWE-331 6.5AI Medium AI 2025-06-19
CVE-2025-24797 Meshtastic incorrectly hands malformed packets leads to controlled buffer overflow CWE-119 9.4 Critical 2025-04-14
CVE-2025-21608 Forged packets over MQTT can show up in direct messages in Meshtastic firmware CWE-668 5.3 - 2025-02-18
CVE-2024-51500 Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmware CWE-138 5.3 Medium 2024-11-04
CVE-2024-47079 Unauthorized usage of remote hardware module because of missing channel verification CWE-345 6.4 Medium 2024-10-07
CVE-2024-47078 Meshtastic firmware Authentication/Authorization Bypass via MQTT CWE-287 8.1 High 2024-09-25
CVE-2024-45038 Device crash via malformed MQTT packet when downlink is enabled in Meshtastic device firmware CWE-755 7.5 High 2024-08-27

All 19 known CVE vulnerabilities affecting firmware with full Chinese analysis, references, and POCs where available.