CWE
1390
Advisory Published
Updated

CVE-2024-41722: goTenna Pro ATAK Plugin Weak Authentication

First published: Thu Sep 26 2024(Updated: )

In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the device is being used in an unencrypted environment or if the cryptography has already been compromised. It is advised to use encryption shared with local QR code for higher security operations.

Credit: ics-cert@hq.dhs.gov

Affected SoftwareAffected VersionHow to fix
goTenna<2.0.7

Remedy

goTenna recommends that users mitigate these vulnerabilities by performing the following updates: * ATAK Plugin: v2.0.7 or greater

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2024-41722?

    CVE-2024-41722 has a high severity rating due to its potential for message injection within goTenna mesh networks.

  • How can CVE-2024-41722 be exploited?

    CVE-2024-41722 can be exploited through the use of a software defined radio to inject custom messages into unencrypted goTenna mesh networks.

  • What versions of goTenna are affected by CVE-2024-41722?

    CVE-2024-41722 affects all versions of goTenna up to 2.0.7.

  • How do I mitigate CVE-2024-41722?

    Mitigating CVE-2024-41722 involves ensuring that goTenna devices are configured to use encryption and applying any available software updates.

  • Who is affected by CVE-2024-41722?

    Organizations using the goTenna Pro ATAK Plugin in unencrypted environments are at risk from CVE-2024-41722.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203