Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Firmware — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in Firmware, with AI-generated Chinese analysis, references, and POCs.

This is a vulnerability aggregation page for firmware products, focusing on weakness type classifications and associated tags. The page compiles a comprehensive database of security vulnerabilities affecting various firmware implementations across different hardware vendors. It covers a wide time range, capturing historical data from early firmware releases up to the most recent security advisories published in the current year. This ensures that users can access both legacy issues and newly discovered threats without missing critical context. Visitors can use this resource to track a vendor's security advisories over time, identifying patterns in patch management and response times. Additionally, the platform allows users to understand a specific weakness class by examining how different firmware architectures are impacted by similar exploit vectors. You can also look up a product's vulnerability history to assess its overall security posture and maintenance quality before deployment. The data is organized to facilitate easy navigation, enabling researchers, security analysts, and system administrators to correlate findings across multiple products. By centralizing this information, the page supports informed decision-making regarding firmware updates and risk mitigation strategies. The content is strictly informational, providing factual details about reported flaws, their severity, and available fixes. This approach helps stakeholders prioritize remediation efforts based on the specific risks associated with their infrastructure.

Vendor: meshtastic

CVE IDTitleCVSSSeverityPublished
CVE-2026-42566 Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failure CWE-20 7.5 High2026-07-19
CVE-2026-44359 Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow CWE-94 10.0 Critical2026-07-19
CVE-2026-11405 Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface --2026-07-06
CVE-2026-7415 Open MQTT orchestration without read/write ACLs in Yarbo robot firmware CWE-306 9.8 Critical2026-05-07
CVE-2026-7414 Hardcoded credentials in Yarbo robot firmware CWE-798 9.8 Critical2026-05-07
CVE-2026-7413 Persistent undocumented backdoor access in Yarbo robot CWE-912 7.2 High2026-05-07
CVE-2025-55292 In Meshtastic, an attacker can spoof licensed amateur flag for a node CWE-348 8.2 High2026-01-27
CVE-2025-53627 Meshtastic firmware allows forged DMs with no PKC to show up as encrypted CWE-1287 5.3 Medium2025-12-29
CVE-2025-55293 Meshtastic allows crafting of specific NodeInfo packets that overwrite any publicKey saved in the NodeDB CWE-287 9.4 Critical2025-08-18
CVE-2024-47065 Traceroute_APP responses are not rate-limited. CWE-799 5.3AIMediumAI2025-07-11
CVE-2025-53637 Meshtastic allows Command Injection in GitHub Action CWE-78 4.1 Medium2025-07-10
CVE-2025-24798 Meshtastic crashes via an unimplemented routing module reply CWE-617 4.3 Medium2025-07-10
CVE-2025-52464 Meshtastic Repeated Public and Private Keypairs CWE-331 6.5AIMediumAI2025-06-19
CVE-2025-24797 Meshtastic incorrectly hands malformed packets leads to controlled buffer overflow CWE-119 9.4 Critical2025-04-14
CVE-2025-21608 Forged packets over MQTT can show up in direct messages in Meshtastic firmware CWE-668 5.3 -2025-02-18
CVE-2024-51500 Failure to check for packets from the broadcast address allows potential DDoS amplification attack in Meshtastic firmware CWE-138 5.3 Medium2024-11-04
CVE-2024-47079 Unauthorized usage of remote hardware module because of missing channel verification CWE-345 6.4 Medium2024-10-07
CVE-2024-47078 Meshtastic firmware Authentication/Authorization Bypass via MQTT CWE-287 8.1 High2024-09-25
CVE-2024-45038 Device crash via malformed MQTT packet when downlink is enabled in Meshtastic device firmware CWE-755 7.5 High2024-08-27

All 19 known CVE vulnerabilities affecting Firmware with full Chinese analysis, references, and POCs where available.