goTenna V1 Weak Authentication Vulnerability Allowing Message Injection

Vulnerability

A vulnerability exists in goTenna V1 devices running app version 5.5.3 and firmware 0.25.5. The issue allows the injection of custom messages into existing V1 networks, using any Group ID (GID) and Callsign, through a software-defined radio. This exploitation is possible in unencrypted environments or if the device's cryptography has been compromised.

Impact

Exploitation of this vulnerability could lead to unauthorized message injection, disrupting communication within the affected goTenna V1 network.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.9
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.