Race Condition Vulnerability in 2FAuth Product by Bubka
CVE-2025-45731

6.5MEDIUM

Key Information:

Vendor

Bubka

Status
Vendor
CVE Published:
24 July 2025

What is CVE-2025-45731?

A race condition in version 5.5.0 of the 2FAuth product allows an attacker to exploit group deletion operations that overlap with other pending actions, resulting in data inconsistencies and the potential creation of orphaned accounts. This scenario occurs when a group is deleted while other operations are still underway, highlighting a significant flaw in synchronizing asynchronous requests.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.