Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.3%top 80%

CVE-2026-42566: CWE-20: Improper Input Validation in meshtastic firmware

0
High
VulnerabilityCVE-2026-42566cvecve-2026-42566cwe-20
Published: 07/19/2026 (07/19/2026, 23:16:04 UTC)
Source: CVE Database V5
Vendor/Project: meshtastic
Product: firmware

Description

Meshtastic firmware versions prior to 2.7.23.b246bcd contain an input validation vulnerability where a malformed User.long_name with improper character encoding can cause BLE management failures on iOS devices. This malformed name can occur naturally due to buffer truncation and leads the iOS app to fail parsing the node database, causing BLE sync loops and loss of device control. The issue propagates through the mesh network, potentially affecting many users. Firmware version 2.7.23.b246bcd and later include input sanitization and regression tests to address this problem, and app updates improve handling of malformed encodings.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

GitHub Actionsmore threats →ai
meshtastic/firmware
pkg:github/meshtastic/firmware

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 13:37:54 UTC

Technical Analysis

CVE-2026-42566 is an improper input validation vulnerability (CWE-20) in Meshtastic firmware prior to version 2.7.23.b246bcd. A node advertising a User.long_name with malformed character encoding—arising from buffer truncation or similar issues—can poison the node database. The iOS app enforces encoding validation and cannot parse the poisoned database, causing BLE sync to fail and enter retry loops, effectively rendering devices unusable via BLE management on iOS. The malformed name propagates through the mesh network, impacting multiple users over a wide area. The vulnerability does not require malicious crafting of the name and has been observed naturally. Starting with version 2.7.23.b246bcd, input sanitization and regression tests have been added to the firmware, and the apps have improved robustness against malformed encoding sequences.

Potential Impact

The vulnerability causes denial of service for iOS users managing Meshtastic radios via BLE, as the iOS app cannot parse the node database containing malformed User.long_name entries. This results in BLE sync fail/retry loops and loss of control over affected devices. The issue can propagate through the mesh network, degrading BLE management for multiple users across a wide geographical area for an extended time. Less technical users have no straightforward recovery method unless they use alternate management tools like the Python CLI. There is no impact on confidentiality or integrity, only availability (denial of service).

Mitigation Recommendations

Firmware version 2.7.23.b246bcd and later include input sanitization to prevent malformed User.long_name entries and regression tests to recover already-poisoned devices. Users should upgrade to this version or later. The Meshtastic apps have also improved handling of malformed encoding sequences to reduce impact. If upgrading is not immediately possible, affected users can use alternate management paths such as the Python CLI to identify and remove malformed entries manually. Patch status is not explicitly confirmed in the advisory; users should verify with the vendor for the latest remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-04-28T17:26:12.084Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null

Threat ID: 6a5d60df2a4a8d5989626f51

Added to database: 07/19/2026, 23:42:23 UTC

Last enriched: 07/30/2026, 13:37:54 UTC

Last updated: 08/16/2026, 12:41:09 UTC

Views: 151

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses