CVE-2021-41716

CRITICAL

Mahavitaran < 7.50 - Unauthenticated Account Takeover via OTP Fixation

Title source: llm
STIX 2.1

Description

Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function

References (2)

Core 2
Core References
Not Applicable x_refsource_misc
http://maharashtra.com

Scores

CVSS v3 9.8
EPSS 0.0137
EPSS Percentile 68.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
mahadiscom/mahavitaran < 7.50
Published Dec 07, 2021
Tracked Since Feb 18, 2026