Vulnerability Description
An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The verification token used for sending SMS through a goTenna server is hardcoded in the app.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gotenna | Mesh Firmware | 1.1.12 |
| Gotenna | Mesh | - |
| Gotenna | Gotenna | 5.5.3 |
Related Weaknesses (CWE)
References
- https://github.com/Dollarhyde/goTenna_v1_and_Mesh_vulnerabilitiesThird Party Advisory
- https://gotenna.comProduct
FAQ
What is CVE-2025-32888?
CVE-2025-32888 is a vulnerability with a CVSS score of 7.3 (HIGH). An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The verification token used for sending SMS through a goTenna server is hardcoded in the app.
How severe is CVE-2025-32888?
CVE-2025-32888 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-32888?
Check the references section above for vendor advisories and patch information. Affected products include: Gotenna Mesh Firmware, Gotenna Mesh, Gotenna Gotenna.