CVE-2025-69615Disclosure(telekom / account_management_portal)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch telekom account_management_portal systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2025-10-24, fixed 2025-11-03.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • account_management_portal

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-19)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
account_management_portal

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-10: 1Mentions · 2026-03-19: 2Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-19: 203-1003-19
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-101
Patch1
2026-03-192
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-69615 Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. Affected Product:… https://www.cve.org/CVERecord?id=CVE-2025-69615

    Post summary

    The post discloses that CVE‑2025‑69615 allows an attacker to brute‑force MFA credentials without rate‑limiting, enabling a full MFA bypass without user interaction.

    00010305
    56.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-69615 Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. Affected Product:… https://www.cve.org/CVERecord?id=CVE-2025-69615 ----- Traducción: CVE-2025-69615 Con… http://infoflow.cloud`

    Post summary

    The post announces CVE-2025-69615, noting a flaw that permits unlimited brute‑force retries and MFA bypass; no PoC, exploit, or patch details are provided.

    0000090
    61 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-69615: CRITICAL] Avoid cyber threats! Deutsche Telekom's Account Management Portal had vulnerabilities allowing unlimited brute-force attacks and MFA bypass. Update to fixed version 2025-11-03.#cve,CVE-2025-69615,#cybersecurity https://cvefind.com/CVE-2025-69615

    Post summary

    The post announces a critical vulnerability (CVE‑2025‑69615) in Deutsche Telekom’s portal that enables brute‑force and MFA bypass, and urges users to upgrade to the fixed 2025‑11‑03 release.

    0000074
    601 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptelekomaccount_management_portal---

Explore more