First published: Thu May 01 2025(Updated: )
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phone number unless they specifically opt out. A phone number is very sensitive information because it can be tied back to individuals. The app does not encrypt the GID in messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
goTenna | ||
goTenna |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32881 has been classified as a medium severity vulnerability due to potential exposure of sensitive user information.
To mitigate CVE-2025-32881, users should opt out of using their phone number as the GID in the app settings.
The primary risk is the exposure of user phone numbers, which can lead to privacy breaches and targeted attacks.
CVE-2025-32881 affects goTenna v1 devices running app version 5.5.3 and firmware version 0.25.5.
No, the GID is not encrypted in messages, making it vulnerable to interception.