CVE-2025-55292Disclosure(meshtastic / meshtastic_firmware)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by their NodeID, generated from the MAC address, rather than their public key. This aspect downgrades the security, specifically by abusing the HAM mode which doesn't use encryption. An attacker can, as such, forge a NodeInfo on behalf of a victim node advertising that the HAM mode is enabled. This, in turn, will allow the other nodes on the mesh to accept the new information and overwriting the NodeDB. The other nodes will then only be able to send direct messages to the victim by using the shared channel key instead of the PKC. Additionally, because HAM mode by design doesn't provide any confidentiality or authentication of information, the attacker could potentially also be able to change the Node details, like the full name, short code, etc. To keep the attack persistent, it is enough to regularly resend the forged NodeInfo, in particular right after the victim sends their own. A patch is available in version 2.7.6.834c3c5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-348

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • meshtastic_firmware

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-01-27); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
meshtastic_firmware

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-01-27: 1Mentions · 2026-01-28: 1Mentions · 2026-02-02: 1Technical Details · 2026-01-28: 1Technical Details · 2026-02-02: 101-2701-2802-02
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-271
General1
2026-01-281
Disclosure1
2026-02-021
Disclosure1
Full discourse3 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-55292 (CVSS:8.2, HIGH) is Undergoing Analysis. Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by t..https://nvd.nist.gov/vuln/detail/CVE-2025-55292 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE‑2025‑55292 is under analysis with a high CVSS score, but no PoC, exploit code, patch, or evidence of active exploitation has been provided.

    0000056
    171 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-55292 Meshtastic NodeID Spoofing Vulnerability in HAM Mode Prior to 2.7.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-55292

    Post summary

    A disclosure of a NodeID spoofing vulnerability affecting Meshtastic devices in HAM mode prior to version 2.7.6.

    0000053
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2025-55292 Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by their NodeID, generated from the MAC address, r… https://www.cve.org/CVERecord?id=CVE-2025-55292

    Post summary

    The text notes the existence of CVE-2025-55292 but offers no technical details, PoC, exploit, or patch information.

    00000291
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSmeshtasticmeshtastic_firmware---

Explore more