CVE-2025-32884
—CVSS 3.1
6.5 medium
EPSS
<1%p5
Published
()
Modified
Description
An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phone number unless they specifically opt out. A phone number is very sensitive information because it can be tied back to individuals. The app does not encrypt the GID in messages.
- Vendors
- gotenna
- Products
- mesh firmware, gotenna
- Weakness
- CWE-319
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.