Vulnerabilities > Gotenna > Low

DATE CVE VULNERABILITY TITLE RISK
2024-09-26 CVE-2024-47127 Improper Authentication vulnerability in Gotenna PRO
In the goTenna Pro App there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks.
high complexity
gotenna CWE-287
3.1
2024-09-26 CVE-2024-47123 Insufficient Verification of Data Authenticity vulnerability in Gotenna PRO
The goTenna Pro App uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms.
high complexity
gotenna CWE-345
3.1