
Proof-of-concept for CVE-2026-7671, demonstrating OTP brute-force on Tornet Scooter Android app due to missing rate limiting on /TwoFactor endpoint.
Improper restriction of excessive authentication attempts (CWE-307) in Tornet Scooter Mobile App 4.75 on Android.
The /TwoFactor endpoint does not implement rate limiting or lockout. A 4-digit OTP (0000-9999) can be brute-forced remotely.