PT-2026-61517 · Unknown · Meshtastic

CVE-2026-42566

·

Published

2026-07-19

·

Updated

2026-08-18

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Meshtastic versions prior to 2.7.23.b246bcd
Description A node advertising a User.long name with malformed character encoding can render other radios unusable over BLE when managed via the iOS app. This issue occurs when a null terminator is placed in the middle of a multibyte sequence, often due to ordinary buffer truncation, resulting in a poisoned node database. Because the iOS app enforces encoding validation, it cannot parse the database once a poisoned entry exists, causing the BLE sync to enter a fail/retry loop and leading to a loss of control over the device. Since the malformed name propagates through the mesh, a single affected node can degrade BLE management for iOS users across a wide geographical area. Users can manually remove offending entries using the Python CLI.
Recommendations Update to version 2.7.23.b246bcd or later. As a temporary workaround, use the Python CLI to identify and manually remove offending entries from the node database.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42566
GHSA-7PH5-2MJV-69H8

Affected Products

Meshtastic