Vulnerabilities
28 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-32889 | An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The verification token used for sending SMS through a goTenna server is hardcoded in the app. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2024-47130 | The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group messages. The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group messages. It is advised to update your app to the current release for enhanced encryption protocols. NVD description · AI analysis pending | 8.7 group max | <1% |
| — | ||
| CVE-2024-45723 | The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF. This only applies to the optional broadcast of an encryption key, so it is advised to share the key with local QR code for higher security operations. NVD description · AI analysis pending | 7.1 group max | <1% |
| — | ||
| CVE-2024-41715 +1 in the same advisory: …43694 | The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of messages. The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payload regardless of the encryption used. NVD description · AI analysis pending | 5.3 group max | <1% |
| — |