Description
Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2025-10-27, fixed 2025-10-31.
References (2)
Core 2
Core References
Scores
CVSS v3
9.4
EPSS
0.0039
EPSS Percentile
30.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-640
Status
published
Products (1)
telekom/account_management_portal
< 2025-10-27
Published
Mar 10, 2026
Tracked Since
Mar 11, 2026