NA - CVE-2024-47075 - LayUI is a native minimalist modular Web UI...
LayUI is a native minimalist modular Web UI component library. Versions prior to 2.9.17 have a DOM Clobbering vulnerability that can lead to Cross-site Scripting (XSS) on web pages where...
NA - CVE-2024-47121 - The goTenna Pro series uses a weak password for...
The goTenna Pro series uses a weak password for the QR broadcast message. If the QR broadcast message is captured over RF it is possible to decrypt it and use it to decrypt all future and past...
NA - CVE-2024-47122 - In the goTenna Pro application, the encryption...
In the goTenna Pro application, the encryption keys are stored along with a static IV on the device. This allows for complete decryption of keys stored on the device. This allows an attacker to...
NA - CVE-2024-47123 - The goTenna Pro series use AES CTR mode for...
The goTenna Pro series use AES CTR mode for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to any attacker that can access the message.
NA - CVE-2024-47124 - The goTenna pro series does not encrypt the...
The goTenna pro series does not encrypt the callsigns of its users. These callsigns reveal information about the users and can also be leveraged for other vulnerabilities.
NA - CVE-2024-47126 - The goTenna Pro series does not use...
The goTenna Pro series does not use SecureRandom when generating its cryptographic keys. The random function in use is not suitable for cryptographic use.
NA - CVE-2024-47127 - In the goTenna Pro there is a vulnerability...
In the goTenna Pro there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing gotenna mesh networks. This...