An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phone number unless they specifically opt out. A phone number is very sensitive information because it can be tied back to individuals. The app does not encrypt the GID in messages.
CVE ID: CVE-2025-32881
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.3
CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vendor: n/a
Product: n/a
EPSS Score: 0.01% (probability of being exploited)
EPSS Percentile: 0.44% (scored less or equal to compared to others)
EPSS Date: 2025-05-30 (when was this score calculated)