CVE-2024-47065
MEDIUMDescription
Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not rate limited. Given that there are SNR measurements attributed to each received transmission, this is a guaranteed way to get a remote station to reliably and continuously respond. You could easily get 100 samples in a short amount of time (estimated 2 minutes), whereas passively doing the same could take hours or days. There are secondary effects that non-ratelimited traceroute does also allow a 2:1 reflected DoS of the network as well, but these concerns are less than the problem with positional confidentiality (other DoS routes exist). This vulnerability is fixed in 2.5.1.
Is your site exposed to CVE-2024-47065?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| meshtastic | meshtastic_firmware |
References
Frequently Asked Questions
What is CVE-2024-47065? +
How severe is CVE-2024-47065? +
What products are affected by CVE-2024-47065? +
How do I check if I'm vulnerable to CVE-2024-47065? +
Related Vulnerabilities
phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. …
This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpoints. An …
This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API …
Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. It allows an arbitrary …
OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the …
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an …