Message Integrity Vulnerability in goTenna Mesh Devices
CVE-2025-32890
5.3MEDIUM
What is CVE-2025-32890?
An encryption vulnerability has been identified in goTenna Mesh devices that utilize a custom encryption implementation. Without adequate integrity checking mechanisms, attackers are able to manipulate messages within the system, potentially compromising the confidentiality and integrity of communications. This issue emphasizes the need for robust security standards in encryption practices.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved