Vulnerability Description
The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an attacker to discover valid usernames within the system. The impact is amplified for accounts that have not configured a mobile number, as the enumeration is specifically tied to this condition. The discovery of these usernames can facilitate subsequent brute force attacks, social engineering attempts, and information leakage, potentially leading to reputational damage, loss of customer trust, and regulatory non-compliance.
CVSS Score
LOW
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-13166?
CVE-2025-13166 is a vulnerability with a CVSS score of 3.7 (LOW). The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. ...
How severe is CVE-2025-13166?
CVE-2025-13166 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-13166?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.