CVE-2026-42566: CWE-20: Improper Input Validation in meshtastic firmware
Meshtastic firmware versions prior to 2.7.23.b246bcd contain an input validation vulnerability where a malformed User.long_name with improper character encoding can cause BLE management failures on iOS devices. This malformed name can occur naturally due to buffer truncation and leads the iOS app to fail parsing the node database, causing BLE sync loops and loss of device control. The issue propagates through the mesh network, potentially affecting many users. Firmware version 2.7.23.b246bcd and later include input sanitization and regression tests to address this problem, and app updates improve handling of malformed encodings.
AI Analysis
Technical Summary
CVE-2026-42566 is an improper input validation vulnerability (CWE-20) in Meshtastic firmware prior to version 2.7.23.b246bcd. A node advertising a User.long_name with malformed character encoding—arising from buffer truncation or similar issues—can poison the node database. The iOS app enforces encoding validation and cannot parse the poisoned database, causing BLE sync to fail and enter retry loops, effectively rendering devices unusable via BLE management on iOS. The malformed name propagates through the mesh network, impacting multiple users over a wide area. The vulnerability does not require malicious crafting of the name and has been observed naturally. Starting with version 2.7.23.b246bcd, input sanitization and regression tests have been added to the firmware, and the apps have improved robustness against malformed encoding sequences.
Potential Impact
The vulnerability causes denial of service for iOS users managing Meshtastic radios via BLE, as the iOS app cannot parse the node database containing malformed User.long_name entries. This results in BLE sync fail/retry loops and loss of control over affected devices. The issue can propagate through the mesh network, degrading BLE management for multiple users across a wide geographical area for an extended time. Less technical users have no straightforward recovery method unless they use alternate management tools like the Python CLI. There is no impact on confidentiality or integrity, only availability (denial of service).
Mitigation Recommendations
Firmware version 2.7.23.b246bcd and later include input sanitization to prevent malformed User.long_name entries and regression tests to recover already-poisoned devices. Users should upgrade to this version or later. The Meshtastic apps have also improved handling of malformed encoding sequences to reduce impact. If upgrading is not immediately possible, affected users can use alternate management paths such as the Python CLI to identify and remove malformed entries manually. Patch status is not explicitly confirmed in the advisory; users should verify with the vendor for the latest remediation guidance.
CVE-2026-42566: CWE-20: Improper Input Validation in meshtastic firmware
Description
Meshtastic firmware versions prior to 2.7.23.b246bcd contain an input validation vulnerability where a malformed User.long_name with improper character encoding can cause BLE management failures on iOS devices. This malformed name can occur naturally due to buffer truncation and leads the iOS app to fail parsing the node database, causing BLE sync loops and loss of device control. The issue propagates through the mesh network, potentially affecting many users. Firmware version 2.7.23.b246bcd and later include input sanitization and regression tests to address this problem, and app updates improve handling of malformed encodings.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-42566 is an improper input validation vulnerability (CWE-20) in Meshtastic firmware prior to version 2.7.23.b246bcd. A node advertising a User.long_name with malformed character encoding—arising from buffer truncation or similar issues—can poison the node database. The iOS app enforces encoding validation and cannot parse the poisoned database, causing BLE sync to fail and enter retry loops, effectively rendering devices unusable via BLE management on iOS. The malformed name propagates through the mesh network, impacting multiple users over a wide area. The vulnerability does not require malicious crafting of the name and has been observed naturally. Starting with version 2.7.23.b246bcd, input sanitization and regression tests have been added to the firmware, and the apps have improved robustness against malformed encoding sequences.
Potential Impact
The vulnerability causes denial of service for iOS users managing Meshtastic radios via BLE, as the iOS app cannot parse the node database containing malformed User.long_name entries. This results in BLE sync fail/retry loops and loss of control over affected devices. The issue can propagate through the mesh network, degrading BLE management for multiple users across a wide geographical area for an extended time. Less technical users have no straightforward recovery method unless they use alternate management tools like the Python CLI. There is no impact on confidentiality or integrity, only availability (denial of service).
Mitigation Recommendations
Firmware version 2.7.23.b246bcd and later include input sanitization to prevent malformed User.long_name entries and regression tests to recover already-poisoned devices. Users should upgrade to this version or later. The Meshtastic apps have also improved handling of malformed encoding sequences to reduce impact. If upgrading is not immediately possible, affected users can use alternate management paths such as the Python CLI to identify and remove malformed entries manually. Patch status is not explicitly confirmed in the advisory; users should verify with the vendor for the latest remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-04-28T17:26:12.084Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5d60df2a4a8d5989626f51
Added to database: 07/19/2026, 23:42:23 UTC
Last enriched: 07/30/2026, 13:37:54 UTC
Last updated: 08/16/2026, 12:41:09 UTC
Views: 151
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.