NONE · 0

CVE-2025-29996

This vulnerability exists in the CAP back office application due to improper implementation of OTP verification mechanism in its API based login. A remote attacker with valid credentials could exploit...

Vulnerability Description

This vulnerability exists in the CAP back office application due to improper implementation of OTP verification mechanism in its API based login. A remote attacker with valid credentials could exploit this vulnerability by manipulating API request URL/payload. Successful exploitation of this vulnerability could allow the attacker to bypass Two-Factor Authentication (2FA) for other user accounts.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-29996?

CVE-2025-29996 is a documented vulnerability. This vulnerability exists in the CAP back office application due to improper implementation of OTP verification mechanism in its API based login. A remote attacker with valid credentials could exploit...

How severe is CVE-2025-29996?

CVSS scoring is not yet available for CVE-2025-29996. Check NVD for updates.

Is there a patch for CVE-2025-29996?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.