Meshtastic
- <= 2.7.22.96dd647
A vulnerability in Meshtastic firmware versions through 2.7.22.96dd647 allows a single node to broadcast a User.long_name with malformed character encoding. This can disrupt the functionality of other radios over Bluetooth Low Energy (BLE) when managed through the iOS app. The issue can arise from normal buffer truncation, leaving a corrupted name in the node database. The iOS app's encoding validation fails to parse databases with such errors, causing a control loss over the affected device. This problem can degrade BLE management for iOS users across a wide area, making devices effectively unusable until the corrupted entry is removed or ages out of the database.
The vulnerability can cause a denial of service by disrupting BLE management for iOS users, leading to a loss of control over affected devices. This issue can persist for an extended period, especially for less technical users who may not have a straightforward recovery path.
The vulnerability can be reproduced by creating a User.long_name that includes a multibyte character, such as an emoji, and then truncating the name in a way that disrupts the encoding. This can be done by manually editing the node database or by using a name that naturally truncates when transmitted over the mesh network. Once the malformed name is introduced, the iOS app will be unable to sync with the affected device, causing it to enter a fail/retry loop.
Users can update to Meshtastic firmware version 2.7.23.b246bcd or later, which includes input sanitization to prevent the issue and allows recovery for devices that were previously affected. Instructions for updating the firmware can be found on the Meshtastic GitHub page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.