goTenna V1 Weak Authentication Vulnerability Allowing Message Injection
Vulnerability
A vulnerability exists in goTenna V1 devices running app version 5.5.3 and firmware 0.25.5. The issue allows the injection of custom messages into existing V1 networks, using any Group ID (GID) and Callsign, through a software-defined radio. This exploitation is possible in unencrypted environments or if the device's cryptography has been compromised.
Impact
Exploitation of this vulnerability could lead to unauthorized message injection, disrupting communication within the affected goTenna V1 network.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
4.9remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
0.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
