PT-2026-61517 · Unknown · Meshtastic
CVE-2026-42566
·
Published
2026-07-19
·
Updated
2026-08-18
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Meshtastic versions prior to 2.7.23.b246bcd
Description
A node advertising a
User.long name with malformed character encoding can render other radios unusable over BLE when managed via the iOS app. This issue occurs when a null terminator is placed in the middle of a multibyte sequence, often due to ordinary buffer truncation, resulting in a poisoned node database. Because the iOS app enforces encoding validation, it cannot parse the database once a poisoned entry exists, causing the BLE sync to enter a fail/retry loop and leading to a loss of control over the device. Since the malformed name propagates through the mesh, a single affected node can degrade BLE management for iOS users across a wide geographical area. Users can manually remove offending entries using the Python CLI.Recommendations
Update to version 2.7.23.b246bcd or later.
As a temporary workaround, use the Python CLI to identify and manually remove offending entries from the node database.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Meshtastic