CVE-2025-32886: Gotenna

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. All packets sent over RF are also sent over UART with USB Shell, allowing someone with local access to gain information about the protocol and intercept sensitive data.

Affected products

  • Gotenna Gotenna: version 5.5.3 only
  • Gotenna Mesh Firmware: version 0.25.5 only

Published 2025-05-01. Last modified 2026-06-17.