CVE-2025-1629

LOW

Excitel App 3.13.0 - Auth Bypass

Title source: llm

Description

A vulnerability was found in Excitel Broadband Private my Excitel App 3.13.0 on Android. It has been classified as problematic. Affected is an unknown function of the component One-Time Password Handler. The manipulation leads to improper restriction of excessive authentication attempts. The vendor was contacted early about this disclosure but did not respond in any way.

Scores

CVSS v3 3.5
EPSS 0.0002
EPSS Percentile 3.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-799 CWE-307
Status draft

Timeline

Published Feb 24, 2025
Tracked Since Feb 18, 2026