CVE-2024-47078 - Meshtastic MQTT Authorization Bypass Vulnerability

3 weeks ago 9
ARTICLE AD BOX
CVE ID : CVE-2024-47078
Published : Sept. 25, 2024, 4:15 p.m. | 24 minutes ago
Description : Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. Nodes can communicate directly via an internet connection or proxied through a connected phone (i.e., via bluetooth). Prior to version 2.5.1, multiple weaknesses in the MQTT implementation allow for authentication and authorization bypasses resulting in unauthorized control of MQTT-connected nodes. Version 2.5.1 contains a patch.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article