Vulnerability Description
An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phone number unless they specifically opt out. A phone number is very sensitive information because it can be tied back to individuals. The app does not encrypt the GID in messages.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gotenna | Mesh Firmware | 1.1.12 |
| Gotenna | Mesh | - |
| Gotenna | Gotenna | 5.5.3 |
Related Weaknesses (CWE)
References
- https://github.com/Dollarhyde/goTenna_v1_and_Mesh_vulnerabilitiesThird Party Advisory
- https://gotenna.comProduct
FAQ
What is CVE-2025-32884?
CVE-2025-32884 is a vulnerability with a CVSS score of 4.3 (MEDIUM). An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phone number unless they specifically opt out. A phone number is very sensitive info...
How severe is CVE-2025-32884?
CVE-2025-32884 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-32884?
Check the references section above for vendor advisories and patch information. Affected products include: Gotenna Mesh Firmware, Gotenna Mesh, Gotenna Gotenna.