Home

Description

Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2025-10-24, fixed 2025-11-03.

PUBLISHED Reserved 2026-01-09 | Published 2026-03-10 | Updated 2026-03-10 | Assigner mitre

References

www.telekom.com/...and-security/news/acknowledgements-358300

gist.github.com/...alrohitt/b3e6d071aac8530459e8b3a5720bb832

cve.org (CVE-2025-69615)

nvd.nist.gov (CVE-2025-69615)

Download JSON