CVE-2025-32884

An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phone number unless they specifically opt out. A phone number is very sensitive information because it can be tied back to individuals. The app does not encrypt the GID in messages.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:gotenna:mesh_firmware:1.1.12:*:*:*:*:*:*:*
cpe:2.3:h:gotenna:mesh:-:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:gotenna:gotenna:5.5.3:*:*:*:*:-:*:*

History

20 Jun 2025, 16:50

Type Values Removed Values Added
CPE cpe:2.3:h:gotenna:mesh:-:*:*:*:*:*:*:*
cpe:2.3:a:gotenna:gotenna:5.5.3:*:*:*:*:-:*:*
cpe:2.3:o:gotenna:mesh_firmware:1.1.12:*:*:*:*:*:*:*
References () https://github.com/Dollarhyde/goTenna_v1_and_Mesh_vulnerabilities - () https://github.com/Dollarhyde/goTenna_v1_and_Mesh_vulnerabilities - Third Party Advisory
References () https://gotenna.com - () https://gotenna.com - Product
First Time Gotenna
Gotenna mesh
Gotenna gotenna
Gotenna mesh Firmware

02 May 2025, 13:52

Type Values Removed Values Added
Summary
  • (es) Se detectó un problema en los dispositivos goTenna Mesh con la aplicación 5.5.3 y el firmware 1.1.12. Por defecto, el GID es el número de teléfono del usuario, a menos que este lo desactive específicamente. Un número de teléfono es información muy sensible, ya que puede asociarse con personas. La aplicación no cifra el GID en los mensajes.

01 May 2025, 20:15

Type Values Removed Values Added
CWE CWE-319

01 May 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-01 18:15

Updated : 2025-06-20 16:50


NVD link : CVE-2025-32884

Mitre link : CVE-2025-32884

CVE.ORG link : CVE-2025-32884


JSON object : View

Products Affected

gotenna

  • gotenna
  • mesh
  • mesh_firmware
CWE
CWE-319

Cleartext Transmission of Sensitive Information