CVE-2025-32886
Last modified
CVE-2025-32886 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. All packets sent over RF are also sent over UART with USB Shell, allowing someone with local access to gain information about the protocol and intercept sensitive data.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. All packets sent over RF are also sent over UART with USB Shell, allowing someone with local access to gain information about the protocol and intercept sensitive data.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gotenna | Mesh Firmware | 0.25.5 |
| Gotenna | Gotenna | 5.5.3 |
References
- https://github.com/Dollarhyde/goTenna_v1_and_Mesh_vulnerabilitiesThird Party Advisory
- https://gotenna.comProduct
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-32886?
How severe is CVE-2025-32886?
How do I fix CVE-2025-32886?
Are you affected by CVE-2025-32886?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
