VYPR
Critical severity9.1NVD Advisory· Published Mar 10, 2026· Updated May 7, 2026

CVE-2025-69615

CVE-2025-69615

Description

Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2025-10-24, fixed 2025-11-03.

Affected products

2
  • cpe:2.3:a:telekom:account_management_portal:*:*:*:*:*:*:*:*
    Range: <=2025-10-24
  • Deutsche Telekom AG/Telekom Account Management Portaldescription

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.