Username Enumeration Vulnerability in EMQ X Dashboard by EMQ Technologies
CVE-2021-46434
5.3MEDIUM
What is CVE-2021-46434?
The EMQ X Dashboard version 3.0.0 is susceptible to a username enumeration vulnerability within the '/api/v3/auth' interface. During the login process, the application exhibits different behaviors based on the validity of the username provided, allowing an attacker to determine if a username is valid or not. This weakness can potentially be exploited to facilitate further attacks, including unauthorized access to accounts.