An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app uses a custom implementation of encryption without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message.
2025-05-01T18:15:55.127
2025-06-20T16:52:25.717
Analyzed
CVSSv3.1: 5.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | gotenna | mesh_firmware | 0.25.5 | Yes |
| Hardware | gotenna | mesh | - | No |
| Application | gotenna | gotenna | 5.5.3 | Yes |