Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-7671 — Proof-of-concept for CVE-2026-7671, demonstrating OTP brute-force on Tornet Scooter Android app due to missing rate limiting on /TwoFactor endpoint. | Kitploit
Tools/GitHubGitHub/caginkyr/cve-2026-7671
Android SecurityVulnerability AnalysisExploitationMobile SecurityAuthentication
GitHubcaginkyr/cve-2026-7671

CVE-2026-7671

Proof-of-concept for CVE-2026-7671, demonstrating OTP brute-force on Tornet Scooter Android app due to missing rate limiting on /TwoFactor endpoint.

View Repository
23 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-7671 - Tornet Scooter OTP Brute Force

Summary

Improper restriction of excessive authentication attempts (CWE-307) in Tornet Scooter Mobile App 4.75 on Android.

Details

The /TwoFactor endpoint does not implement rate limiting or lockout. A 4-digit OTP (0000-9999) can be brute-forced remotely.

Timeline

  • 2025-10-24: Vendor notified
  • 2026-04-08: Public disclosure (no vendor response)
  • 2026-05-02: CVE-2026-7671 assigned

References

  • https://vuldb.com/?id.360819
  • https://www.cve.org/CVERecord?id=CVE-2026-7671
Download Tool