An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. It uses a custom implementation of encryption without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message.
| Software | From | Fixed in |
|---|---|---|
| gotenna / mesh_firmware | 1.1.12 | 1.1.12.x |
| gotenna / gotenna | 5.5.3 | 5.5.3.x |