ZeroHour

Vulnerabilities

28 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-32889
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5.

An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The verification token used for sending SMS through a goTenna server is hardcoded in the app.

NVD description · AI analysis pending
8.8
group max
<1%
  • gotenna mesh firmware
  • gotenna gotenna
CVE-2024-47130
The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group messages.

The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group messages. It is advised to update your app to the current release for enhanced encryption protocols.

NVD description · AI analysis pending
8.7
group max
<1%
  • gotenna gotenna pro
CVE-2024-45723
The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys.

The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF. This only applies to the optional broadcast of an encryption key, so it is advised to share the key with local QR code for higher security operations.

NVD description · AI analysis pending
7.1
group max
<1%
  • gotenna gotenna
CVE-2024-41715
+1 in the same advisory: …43694
The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of messages.

The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payload regardless of the encryption used.

NVD description · AI analysis pending
5.3
group max
<1%
  • gotenna atak plugin