Successful exploitation of this vulnerability could allow the attacker to bypass Two-Factor Authentication (2FA) for other user accounts.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade RupeeWeb to version 66.9
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-4208 | This vulnerability exists in RupeeWeb trading platform due to improper implementation of OTP validation mechanism in certain API endpoints. A remote attacker with valid credentials could exploit this vulnerability by manipulating API responses. Successful exploitation of this vulnerability could allow the attacker to bypass Two-Factor Authentication (2FA) for other user accounts. |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 14 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Feb 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authentication Bypass Vulnerability in RupeeWeb trading platform | Authentication Bypass Vulnerability in RupeeWeb trading platform |
Fri, 14 Feb 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in RupeeWeb trading platform due to improper implementation of OTP validation mechanism in certain API endpoints. A remote attacker with valid credentials could exploit this vulnerability by manipulating API responses. Successful exploitation of this vulnerability could allow the attacker to bypass Two-Factor Authentication (2FA) for other user accounts. | |
| Title | Authentication Bypass Vulnerability in RupeeWeb trading platform | |
| Weaknesses | CWE-302 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2025-02-14T16:33:17.339Z
Reserved: 2025-02-12T11:42:37.480Z
Link: CVE-2025-26522
Updated: 2025-02-14T16:33:13.477Z
Status : Deferred
Published: 2025-02-14T12:15:29.583
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-26522
No data.
OpenCVE Enrichment
No data.
EUVD