Gotenna manufactures a family of compact off-grid communication devices designed for mesh networking and emergency connectivity, including the Gotenna and Gotenna Pro handhelds and their associated firmware and software plugins. The vendor's vulnerability profile centers on data-handling and cryptographic-implementation weaknesses, particularly cleartext transmission of sensitive information, inadequate integrity checking, and insecure storage practices that are characteristic of devices operating in constrained or disconnected environments. These weakness classes reflect the tension between the product's durability and portability goals and the security demands of a communication platform entrusted with potentially sensitive coordination data. Defenders deploying these devices in operational contexts should prioritize network segmentation and evaluate whether cleartext or weakly protected communications meet their confidentiality and integrity requirements; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gotenna over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-32889HIGH An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The verification token used for sending SMS through a goTenna server is hardcoded in the app. | May 1, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-32888HIGH An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The verification token used for sending SMS through a goTenna server is hardcoded in the app. | May 1, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-47126HIGH The goTenna Pro App does not use SecureRandom when generating passwords
for sharing cryptographic keys. The random function in use makes it
easier for attackers to brute force th | Sep 26, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-32887MEDIUM An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. A command channel includes the next hop. which can be intercepted and used to break frequency hopp | May 1, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-32885MEDIUM An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app there makes it possible to inject any custom message (into existing v1 networks) with any | May 1, 2025 | 6.5 | 20 | NO | NO |
CVE-2024-47130MEDIUM The goTenna Pro App allows unauthenticated attackers to remotely update
the local public keys used for P2P and group messages. It is advised to
update your app to the current rel | Sep 26, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-47122MEDIUM In the goTenna Pro App, the encryption keys are stored along with a
static IV on the End User Device (EUD). This allows for complete
decryption of keys stored on the EUD if physi | Sep 26, 2024 | 6.5 | 20 | NO | NO |
CVE-2025-32890MEDIUM An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. It uses a custom implementation of encryption without any additional integrity checking mechanis | May 1, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-32884MEDIUM An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phone number unless they specifically opt out. A phone number is | May 1, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-32882MEDIUM An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app uses a custom implementation of encryption without any additional integrity checking mecha | May 1, 2025 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gotenna.
Media articles that mention a CVE ID that affects a product developed by Gotenna — matched by CVE ID, not by vendor name.