Message Impersonation in Meshtastic-Android App by Meshtastic
CVE-2025-52883

5.3MEDIUM

Key Information:

Vendor

Meshtastic

Vendor
CVE Published:
24 June 2025

What is CVE-2025-52883?

The Meshtastic-Android application, designed for mesh radio communication, features a vulnerability in which an attacker can send unencrypted messages while impersonating another node in the mesh network. This exploit displays the message in the user's standard chat interface, misleading the victim into believing the communication is secured with Public Key Cryptography (PKC) due to the incorrect green padlock indicator. This false sense of security can lead users to unwittingly trust malicious messages as legitimate. Version 2.5.21 includes a patch that enhances message verification methods. Users should ensure they are running the latest version and consider additional safeguards for messaging clarity.

Affected Version(s)

Meshtastic-Android < 2.5.21

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52883 : Message Impersonation in Meshtastic-Android App by Meshtastic