Brute Force Vulnerability in Meon KYC Solutions
CVE-2025-42600

8.2HIGH

Key Information:

Vendor

Meon

Vendor
CVE Published:
23 April 2025

What is CVE-2025-42600?

This vulnerability in Meon KYC solutions stems from inadequate safeguards on the allowed number of failed One-Time Password (OTP) attempts. Attackers can exploit the flaw through a brute force approach, targeting the API endpoints related to the login procedure. Successful exploitation could allow unauthorized access to user accounts, posing serious security risks. Organizations using Meon KYC solutions should implement measures to limit OTP attempts and enhance protection against such attacks.

Affected Version(s)

KYC solutions 1.1

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability is reported by Mohit Gadiya.
.