Message Impersonation in Meshtastic-Android App by Meshtastic
CVE-2025-52883
What is CVE-2025-52883?
The Meshtastic-Android application, designed for mesh radio communication, features a vulnerability in which an attacker can send unencrypted messages while impersonating another node in the mesh network. This exploit displays the message in the user's standard chat interface, misleading the victim into believing the communication is secured with Public Key Cryptography (PKC) due to the incorrect green padlock indicator. This false sense of security can lead users to unwittingly trust malicious messages as legitimate. Version 2.5.21 includes a patch that enhances message verification methods. Users should ensure they are running the latest version and consider additional safeguards for messaging clarity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Meshtastic-Android < 2.5.21
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
