Message Impersonation in Meshtastic-Android App by Meshtastic
CVE-2025-52883
5.3MEDIUM
What is CVE-2025-52883?
The Meshtastic-Android application, designed for mesh radio communication, features a vulnerability in which an attacker can send unencrypted messages while impersonating another node in the mesh network. This exploit displays the message in the user's standard chat interface, misleading the victim into believing the communication is secured with Public Key Cryptography (PKC) due to the incorrect green padlock indicator. This false sense of security can lead users to unwittingly trust malicious messages as legitimate. Version 2.5.21 includes a patch that enhances message verification methods. Users should ensure they are running the latest version and consider additional safeguards for messaging clarity.
Affected Version(s)
Meshtastic-Android < 2.5.21