CVE-2025-32882

MEDIUM

goTenna <5.5.3-0.25.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app uses a custom implementation of encryption without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message.

Scores

CVSS v3 5.3
EPSS 0.0003
EPSS Percentile 6.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-353
Status published
Products (2)
gotenna/gotenna 5.5.3
gotenna/mesh_firmware 0.25.5
Published May 01, 2025
Tracked Since Feb 18, 2026