CVE-2024-41931: Gotenna

Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.

The goTenna Pro ATAK Plugin encryption key name is always sent unencrypted when the key is sent over RF through a broadcast message. It is advised to share the encryption key via local QR for higher security operations.

Affected products

  • Gotenna Gotenna: before 2.0.7 (fixed in 2.0.7)

Published 2024-09-26. Last modified 2026-06-17.