Improper Authentication in CodeWise Tornet Scooter Mobile App for iOS and Android
CVE-2026-7671
Key Information:
- Vendor
Codewise
- Vendor
- CVE Published:
- 2 May 2026
Badges
What is CVE-2026-7671?
The CodeWise Tornet Scooter Mobile App version 4.75 for both iOS and Android is exposed to a vulnerability that allows for improper restriction of excessive authentication attempts through an undisclosed function in the file /TwoFactor. This flaw enables attackers to potentially exploit the system from a remote location, making interception and manipulation of authentication protocols a serious concern. Despite the complexity associated with the attacks, the vulnerability has been publicly disclosed, creating potential risks for users who have not implemented necessary security measures. CodeWise Technologies was informed of this security flaw but has yet to provide a response.
Affected Version(s)
Tornet Scooter Mobile App 4.75
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
