Rate Limiting Vulnerability in Meshtastic Open Source Mesh Networking Solution
CVE-2024-47065

2.7LOW

Key Information:

Vendor

Meshtastic

Status
Vendor
CVE Published:
11 July 2025

What is CVE-2024-47065?

Meshtastic, an open source mesh networking solution, has a vulnerability present in versions prior to 2.5.1 related to the handling of traceroute responses. Specifically, these responses are not subject to rate limiting, allowing for potential abuse. An attacker could exploit this flaw to induce a high volume of traceroute requests, receiving up to 100 samples in a mere two minutes. This could impact the positional confidentiality of network stations. Furthermore, the lack of rate limiting could lead to denial of service conditions, resulting in network disruptions. The vulnerability has been effectively addressed in version 2.5.1.

Affected Version(s)

firmware < 2.5.1

References

CVSS V4

Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-47065 : Rate Limiting Vulnerability in Meshtastic Open Source Mesh Networking Solution