CVE-2024-41722

MEDIUM

goTenna Pro ATAK Plugin - Code Injection

Title source: llm
STIX 2.1

Description

In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the device is being used in an unencrypted environment or if the cryptography has already been compromised. It is advised to use encryption shared with local QR code for higher security operations.

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 13.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1390
Status published
Products (1)
gotenna/gotenna < 2.0.7
Published Sep 26, 2024
Tracked Since Feb 18, 2026