First published: Thu May 01 2025(Updated: )
An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phone number unless they specifically opt out. A phone number is very sensitive information because it can be tied back to individuals. The app does not encrypt the GID in messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
goTenna Mesh Firmware | ||
goTenna Mesh Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32884 is a serious vulnerability due to the exposure of sensitive user phone numbers as GIDs without encryption.
To mitigate CVE-2025-32884, users should update their goTenna Mesh devices to the latest firmware that addresses this vulnerability.
The risks associated with CVE-2025-32884 include potential privacy breaches as user phone numbers can be exposed to unauthorized parties.
CVE-2025-32884 specifically affects goTenna Mesh devices running app version 5.5.3 and firmware version 1.1.12.
Due to CVE-2025-32884, users' phone numbers, which serve as their GIDs, are exposed in unencrypted messages.