CVE-2025-1629 Details
Description
A vulnerability was found in Excitel Broadband Private my Excitel App 3.13.0 on Android. It has been classified as problematic. Affected is an unknown function of the component One-Time Password Handler. The manipulation leads to improper restriction of excessive authentication attempts. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability exists in the Excitel Broadband Private my Excitel App for Android, specifically in version 3.13.0. The issue arises in the One-Time Password (OTP) verification process, where inadequate measures are in place to limit excessive authentication attempts. This flaw allows for brute-force attacks on the OTP, as the app does not effectively prevent multiple rapid attempts to guess the 6-digit code. Exploitation of this vulnerability could lead to unauthorized access to user accounts, allowing attackers to view sensitive information such as KYC documents, and to change passwords or Wi-Fi connection settings. The vulnerability has been classified under CWE-307, relating to excessive authentication attempts.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 24, 2025CISA-ADP
Assessed Feb 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/?ctiid.296610 | [email protected] | Broken Link |
| https://vuldb.com/?id.296610 | [email protected] | AdvisoryTechnical Description |
| https://vuldb.com/?submit.501868 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | [email protected] |
| CWE-799 | Improper Control of Interaction Frequency | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Excitel Broadband Private my Excitel App | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 24, 2025 | New CVE Received | [email protected] |
Volerion