216.73.217.80

CVE-2025-26522

· Published 14/02/2025 12:15 · Modified 14/02/2025 12:15

Labels: CVE-2025-26522 2025-02-14CVE-2025-26522CWE-302[email protected]

Essential information

Published
14/02/2025 12:15
Modified
14/02/2025 12:15
Author
Creator
CISA KEV
No
CWE

Description

This vulnerability exists in RupeeWeb trading platform due to improper implementation of OTP validation mechanism in certain API endpoints. A remote attacker with valid credentials could exploit this vulnerability by manipulating API responses. Successful exploitation of this vulnerability could allow the attacker to bypass Two-Factor Authentication (2FA) for other user accounts.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References