An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app uses a custom implementation of encryption without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message.
| Software | From | Fixed in |
|---|---|---|
| gotenna / mesh_firmware | 0.25.5 | 0.25.5.x |
| gotenna / gotenna | 5.5.3 | 5.5.3.x |