8.2 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
47 packages
- python313Packages.ha-silabs-firmware-client
- ghidra-extensions.ghidra-firmware-utils
- azure-cli-extensions.firmwareanalysis
- ath9k-htc-blobless-firmware-unstable
- python313Packages.virt-firmware
- python312Packages.virt-firmware
- armTrustedFirmwareAllwinnerH6
- armTrustedFirmwareAllwinnerH616
- nitrokey-storage-firmware
- armTrustedFirmwareAllwinner
- ath9k-htc-blobless-firmware
- raspberrypiWirelessFirmware
- nitrokey-trng-rs232-firmware
- armTrustedFirmwareRK3568
- armTrustedFirmwareRK3588
- armTrustedFirmwareRK3399
- armTrustedFirmwareRK3328
- sigrok-firmware-fx2lafw
- nitrokey-start-firmware
- b43Firmware_5_1_138
- facetimehd-firmware
- intel2200BGFirmware
- xow_dongle-firmware
- broadcom-bt-firmware
- uefi-firmware-parser
- nitrokey-pro-firmware
- armTrustedFirmwareQemu
- armTrustedFirmwareS905
- libreelec-dvb-firmware
- armTrustedFirmwareTools
- b43Firmware_6_30_163_46
- nitrokey-fido2-firmware
- rtl8192su-firmware
- system76-firmware
- rtl8761b-firmware
- klipper-firmware
- firmware-updater
- armbian-firmware
- firmware-manager
- zd1211fw
- sof-firmware
- alsa-firmware
- ivsc-firmware
- raspberrypifw
- gnome-firmware
- linux-firmware
- rt5677-firmware
- @LeSuisse dismissed
In Meshtastic, an attacker can spoof licensed amateur flag for a node
Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by their NodeID, generated from the MAC address, rather than their public key. This aspect downgrades the security, specifically by abusing the HAM mode which doesn't use encryption. An attacker can, as such, forge a NodeInfo on behalf of a victim node advertising that the HAM mode is enabled. This, in turn, will allow the other nodes on the mesh to accept the new information and overwriting the NodeDB. The other nodes will then only be able to send direct messages to the victim by using the shared channel key instead of the PKC. Additionally, because HAM mode by design doesn't provide any confidentiality or authentication of information, the attacker could potentially also be able to change the Node details, like the full name, short code, etc. To keep the attack persistent, it is enough to regularly resend the forged NodeInfo, in particular right after the victim sends their own. A patch is available in version 2.7.6.834c3c5.
References
Affected products
- ==<= 2.6.2
Ignored packages (47)
pkgs.zd1211fw
Firmware for the ZyDAS ZD1211(b) 802.11a/b/g USB WLAN chip
pkgs.sof-firmware
Sound Open Firmware
pkgs.alsa-firmware
Soundcard firmwares from the alsa project
pkgs.ivsc-firmware
Firmware binaries for the Intel Vision Sensing Controller
-
nixos-unstable 2024-06-14
- nixpkgs-unstable 2024-06-14
- nixos-unstable-small 2024-06-14
pkgs.raspberrypifw
Firmware for the Raspberry Pi board
-
nixos-unstable 1.20250430
- nixpkgs-unstable 1.20250430
- nixos-unstable-small 1.20250430
pkgs.gnome-firmware
Tool for installing firmware on devices
pkgs.linux-firmware
Binary firmware collection packaged by kernel.org
pkgs.rt5677-firmware
Firmware for Realtek rt5677 device
pkgs.armbian-firmware
Firmware from Armbian
-
nixos-unstable 0-unstable-2023-09-16
- nixpkgs-unstable 0-unstable-2023-09-16
- nixos-unstable-small 0-unstable-2023-09-16
pkgs.firmware-manager
Graphical frontend for firmware management
pkgs.firmware-updater
Firmware Updater for Linux
-
nixos-unstable 0-unstable-2025-09-09
- nixpkgs-unstable 0-unstable-2025-09-09
- nixos-unstable-small 0-unstable-2025-09-09
pkgs.klipper-firmware
Firmware part of Klipper
-
nixos-unstable 0.13.0-unstable-2025-11-17
- nixpkgs-unstable 0.13.0-unstable-2025-10-27
- nixos-unstable-small 0.13.0-unstable-2025-11-17
pkgs.rtl8761b-firmware
Firmware for Realtek RTL8761b
pkgs.system76-firmware
Tools for managing firmware updates for system76 devices
pkgs.rtl8192su-firmware
Firmware for Realtek RTL8188SU/RTL8191SU/RTL8192SU
-
nixos-unstable 0-unstable-2016-10-05
- nixpkgs-unstable 0-unstable-2016-10-05
- nixos-unstable-small 0-unstable-2016-10-05
pkgs.b43Firmware_5_1_138
Firmware for cards supported by the b43 kernel module
pkgs.facetimehd-firmware
facetimehd firmware
pkgs.intel2200BGFirmware
Firmware for Intel 2200BG cards
pkgs.xow_dongle-firmware
Xbox One wireless dongle firmware
-
nixos-unstable 0-unstable-2025-04-22
- nixpkgs-unstable 0-unstable-2025-04-22
- nixos-unstable-small 0-unstable-2025-04-22
pkgs.broadcom-bt-firmware
Firmware for Broadcom WIDCOMM® Bluetooth devices
-
nixos-unstable 12.0.1.1012
- nixpkgs-unstable 12.0.1.1012
- nixos-unstable-small 12.0.1.1012
pkgs.uefi-firmware-parser
Tool for parsing, extracting, and recreating UEFI firmware volumes
pkgs.nitrokey-pro-firmware
Firmware for the Nitrokey Pro device
pkgs.armTrustedFirmwareQemu
Reference implementation of secure world software for ARMv8-A
pkgs.armTrustedFirmwareS905
Reference implementation of secure world software for ARMv8-A
pkgs.libreelec-dvb-firmware
DVB firmware from LibreELEC
pkgs.armTrustedFirmwareTools
Reference implementation of secure world software for ARMv8-A
pkgs.b43Firmware_6_30_163_46
Firmware for cards supported by the b43 kernel module
-
nixos-unstable 6.30.163.46
- nixpkgs-unstable 6.30.163.46
- nixos-unstable-small 6.30.163.46
pkgs.nitrokey-fido2-firmware
Firmware for the Nitrokey FIDO2 device
-
nixos-unstable fido2-firmware-2.4.1
- nixpkgs-unstable fido2-firmware-2.4.1
- nixos-unstable-small fido2-firmware-2.4.1
pkgs.nitrokey-start-firmware
Firmware for the Nitrokey Start device
pkgs.sigrok-firmware-fx2lafw
Firmware for FX2 logic analyzers
-
nixos-unstable fx2lafw-0.1.7-unstable-2024-02-03
- nixpkgs-unstable fx2lafw-0.1.7-unstable-2024-02-03
- nixos-unstable-small fx2lafw-0.1.7-unstable-2024-02-03
pkgs.armTrustedFirmwareRK3328
Reference implementation of secure world software for ARMv8-A
-
nixos-unstable rk3328-2.13.0
- nixpkgs-unstable rk3328-2.13.0
- nixos-unstable-small rk3328-2.13.0
pkgs.armTrustedFirmwareRK3399
Reference implementation of secure world software for ARMv8-A
-
nixos-unstable rk3399-2.13.0
- nixpkgs-unstable rk3399-2.13.0
- nixos-unstable-small rk3399-2.13.0
pkgs.armTrustedFirmwareRK3568
Reference implementation of secure world software for ARMv8-A
-
nixos-unstable rk3568-2.13.0
- nixpkgs-unstable rk3568-2.13.0
- nixos-unstable-small rk3568-2.13.0
pkgs.armTrustedFirmwareRK3588
Reference implementation of secure world software for ARMv8-A
-
nixos-unstable rk3588-2.13.0
- nixpkgs-unstable rk3588-2.13.0
- nixos-unstable-small rk3588-2.13.0
pkgs.nitrokey-storage-firmware
Firmware for the Nitrokey Storage device
pkgs.armTrustedFirmwareAllwinner
Reference implementation of secure world software for ARMv8-A
-
nixos-unstable sun50i_a64-2.13.0
- nixpkgs-unstable sun50i_a64-2.13.0
- nixos-unstable-small sun50i_a64-2.13.0
pkgs.ath9k-htc-blobless-firmware
Blobless, open source wifi firmware for ath9k_htc.ko
pkgs.raspberrypiWirelessFirmware
Firmware for builtin Wifi/Bluetooth devices in the Raspberry Pi 3+ and Zero W
-
nixos-unstable 0-unstable-2025-04-08
- nixpkgs-unstable 0-unstable-2025-04-08
- nixos-unstable-small 0-unstable-2025-04-08
pkgs.nitrokey-trng-rs232-firmware
Firmware for the Nitrokey TRNG RS232 device
-
nixos-unstable rs232-firmware-1.0.0
- nixpkgs-unstable rs232-firmware-1.0.0
- nixos-unstable-small rs232-firmware-1.0.0
pkgs.armTrustedFirmwareAllwinnerH6
Reference implementation of secure world software for ARMv8-A
-
nixos-unstable sun50i_h6-2.13.0
- nixpkgs-unstable sun50i_h6-2.13.0
- nixos-unstable-small sun50i_h6-2.13.0
pkgs.armTrustedFirmwareAllwinnerH616
Reference implementation of secure world software for ARMv8-A
-
nixos-unstable sun50i_h616-2.13.0
- nixpkgs-unstable sun50i_h616-2.13.0
- nixos-unstable-small sun50i_h616-2.13.0
pkgs.python312Packages.virt-firmware
Tools for virtual machine firmware volumes
pkgs.python313Packages.virt-firmware
Tools for virtual machine firmware volumes
pkgs.ath9k-htc-blobless-firmware-unstable
Blobless, open source wifi firmware for ath9k_htc.ko
-
nixos-unstable 2022-05-22
- nixpkgs-unstable 2022-05-22
- nixos-unstable-small 2022-05-22
pkgs.azure-cli-extensions.firmwareanalysis
Microsoft Azure Command-Line Tools Firmwareanalysis Extension
pkgs.ghidra-extensions.ghidra-firmware-utils
Ghidra utilities for analyzing PC firmware
-
nixos-unstable 2024.04.20
- nixpkgs-unstable 2024.04.20
- nixos-unstable-small 2024.04.20
pkgs.python313Packages.ha-silabs-firmware-client
Home Assistant client for firmwares released with silabs-firmware-builder