An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. It uses a custom implementation of encryption without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message.
Exploitability
AC:HAV:APR:NUI:NScope
S:UImpact
A:NC:NI:H5.3/CVSS:3.1/AC:H/AV:A/A:N/C:N/I:H/PR:N/S:U/UI:N