Critical cryptographic flaw in Meshtastic Mesh Networking platform exposes private communications
Meshtastic, an open-source mesh networking solution for off-grid communication, has patched a critical vulnerability (CVE-2025-52464) that allowed attackers to decrypt private messages and hijack remote device administration due to identical cryptographic keys being shipped by manufacturers and poor randomness initialization. Users are urged to update to firmware version 2.6.11 or later and perform factory resets to eliminate potentially compromised keys.
**If you have Meshtastic devices, check the firmware. If it's 2.5.0 and above, it's very wise to update to firmware version 2.6.11 or later. Because attackers can read your private messages and take control of your devices. If possible, patch directly or reach out to your device manufacturer for a patch. After updating, perform a factory reset using "meshtastic --factory-reset-device" to clean up the old and potentially compromised encryption keys.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-cryptographic-flaw-in-meshtastic-mesh-networking-platform-exposes-private-communications-a-x-6-u-s/gD2P6Ple2L