VulnerabilityAnalyzed
CVE-2025-32886
All packets sent over RF are also sent over UART with USB Shell, allowing someone with local access to gain information about the protocol and intercept sensitive data.
MEDIUM 5.5EPSS 0.14%
Does this matter?
Lower severity and a low EPSS score (0.14%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. All packets sent over RF are also sent over UART with USB Shell, allowing someone with local access to gain information about the protocol and intercept sensitive data.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.14% probability · 4th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-923
- Affected
- gotenna/mesh firmware · gotenna/gotenna
- Source
- cve@mitre.org
References
- https://github.com/Dollarhyde/goTenna_v1_and_Mesh_vulnerabilitiesThird Party Advisory
- https://gotenna.comProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.