Improper Authentication in CodeWise Tornet Scooter Mobile App for iOS and Android
CVE-2026-7671

6.3MEDIUM

Key Information:

Vendor

Codewise

Vendor
CVE Published:
2 May 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-7671?

The CodeWise Tornet Scooter Mobile App version 4.75 for both iOS and Android is exposed to a vulnerability that allows for improper restriction of excessive authentication attempts through an undisclosed function in the file /TwoFactor. This flaw enables attackers to potentially exploit the system from a remote location, making interception and manipulation of authentication protocols a serious concern. Despite the complexity associated with the attacks, the vulnerability has been publicly disclosed, creating potential risks for users who have not implemented necessary security measures. CodeWise Technologies was informed of this security flaw but has yet to provide a response.

Affected Version(s)

Tornet Scooter Mobile App 4.75

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

caginkyr (VulDB User)
caginkyr (VulDB User)
VulDB CNA Team
.