Message Integrity Vulnerability in goTenna Mesh Devices
CVE-2025-32890

5.3MEDIUM

Key Information:

Vendor

goTenna

Vendor
CVE Published:
1 May 2025

What is CVE-2025-32890?

An encryption vulnerability has been identified in goTenna Mesh devices that utilize a custom encryption implementation. Without adequate integrity checking mechanisms, attackers are able to manipulate messages within the system, potentially compromising the confidentiality and integrity of communications. This issue emphasizes the need for robust security standards in encryption practices.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.