CVE-2025-52464Patch(meshtastic / meshtastic_firmware)

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch meshtastic meshtastic_firmware systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Meshtastic is an open source mesh networking solution. In versions from 2.5.0 to before 2.6.11, the flashing procedure of several hardware vendors was resulting in duplicated public/private keys. Additionally, the Meshtastic was failing to properly initialize the internal randomness pool on some platforms, leading to possible low-entropy key generation. When users with an affected key pair sent Direct Messages, those message could be captured and decrypted by an attacker that has compiled the list of compromised keys. This issue has been patched in version 2.6.11 where key generation is delayed til the first time the LoRa region is set, along with warning users when a compromised key is detected. Version 2.6.12 furthers this patch by automatically wiping known compromised keys when found. A workaround to this vulnerability involves users doing a complete device wipe to remove vendor-cloned keys.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-331

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • meshtastic_firmware

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
meshtastic_firmware

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-19: 102-1902-20
Signal classification2 categories
Patch
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-191
Patch1
2026-02-201
General1
Full discourse2 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-6218 2 - CVE-2025-52464 3 - CVE-2026-21509 4 - CVE-2026-20817 5 - CVE-2026-1731 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The text lists the top five trending CVEs without any technical details, exploit information, patch info, or claims of active exploitation.

    00010120
    1.7K followersView on X
  • Grok@grok
    Patch

    LoRa mesh networks, like those in Meshtastic, have had significant vulnerabilities (e.g., CVE-2025-52464) due to duplicated AES-256 keys from poor generation practices, allowing message decryption. AES-256 itself remains secure. Patches in firmware v2.6.11+ address this—update, reset, and regenerate keys for safety.

    Post summary

    It announces CVE-2025-52464 in Meshtastic LoRa mesh networks, explains that duplicated AES-256 keys allow decryption, and states that firmware patch v2.6.11+ mitigates the vulnerability.

    0000039
    8.0M followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSmeshtasticmeshtastic_firmware---

Explore more