📦 Gotenna

by Gotenna

🔍 What is Gotenna?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-32889

HIGH CVSS 7.3 May 1, 2025

This vulnerability allows attackers to send SMS messages through goTenna servers without authorization by using a hardcoded verification token in the app. It affects goTenna v1 device users running ap...

CVE-2025-32887

HIGH CVSS 7.1 May 1, 2025

This vulnerability in goTenna v1 devices allows attackers to intercept command channels containing next-hop information, which can be used to break frequency hopping security. This affects users of go...

CVE-2025-32884

MEDIUM CVSS 4.3 May 1, 2025

goTenna Mesh devices with vulnerable app/firmware versions transmit user phone numbers unencrypted in messages by default. This allows attackers intercepting communications to link device activity to ...

CVE-2025-32886

MEDIUM CVSS 4.0 May 1, 2025

This vulnerability allows local attackers to intercept sensitive data transmitted by goTenna v1 devices. When packets are sent over RF, they are also transmitted over UART with USB Shell, exposing pro...

CVE-2025-32881

MEDIUM CVSS 4.3 May 1, 2025

This vulnerability exposes users' phone numbers in goTenna v1 devices by transmitting them unencrypted as Group IDs (GIDs) in messages. Anyone using goTenna v1 devices with the specified app and firmw...

CVE-2024-45838

MEDIUM CVSS 4.3 Sep 26, 2024

The goTenna Pro ATAK Plugin fails to encrypt callsigns in messages, potentially exposing sensitive information to unauthorized observers. This affects users of the goTenna Pro ATAK Plugin who transmit...

CVE-2024-43814

MEDIUM CVSS 4.3 Sep 26, 2024

The goTenna Pro ATAK Plugin's default settings broadcast user location data every 60 seconds without encryption when the plugin is active. This vulnerability allows unauthorized parties to track users...

CVE-2024-45374

MEDIUM CVSS 5.3 Sep 26, 2024

The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via RF broadcast, allowing attackers who capture the broadcast to potentially brute-force the password and decrypt all mess...

CVE-2024-41722

MEDIUM CVSS 6.5 Sep 26, 2024

The goTenna Pro ATAK Plugin vulnerability allows attackers to inject forged messages with arbitrary group IDs and callsigns into goTenna mesh networks using software-defined radio. This affects users ...

CVE-2024-43108

MEDIUM CVSS 5.3 Sep 26, 2024

CVE-2024-43108 is a cryptographic vulnerability in the goTenna Pro ATAK Plugin where encrypted messages lack integrity checking, allowing attackers to modify encrypted content without detection. This ...