VYPR

Mesh

by Decocms

CVEs (4)

  • CVE-2025-14660MedDec 14, 2025
    risk 0.29cvss 5.6epss 0.00

    A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of the file packages/sdk/src/mcp/teams/api.ts of the component Workspace Domain Handler. This manipulation of the argument domain causes improper access…

  • CVE-2025-32884May 1, 2025
    risk 0.00cvss epss 0.00

    An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phone number unless they specifically opt out. A phone number is very sensitive information because it can be tied back to individuals. The app does not encrypt…

  • CVE-2025-32890May 1, 2025
    risk 0.00cvss epss 0.00

    An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. It uses a custom implementation of encryption without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message.

  • CVE-2025-32888May 1, 2025
    risk 0.00cvss epss 0.00

    An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The verification token used for sending SMS through a goTenna server is hardcoded in the app.