← back
CVE-2024-47127

Weak Authentication in goTenna Pro

CVSS 6 MEDIUMEPSS 0.1%CWE-1390
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
26 Sep 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In the goTenna Pro App there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the device is being used in an unencrypted environment or if the cryptography has already been compromised. It is advised to share encryption keys via QR scanning for higher security operations and update your app to the current release for enhanced encryption protocols.
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
goTenna · Pro

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →