Description

Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By hooking into app crypto routines and intercepting decryption paths, attacker can recover plaintext secrets, enabling generation of valid one-time passwords, and bypassing authentication for enrolled accounts.

INFO

Published Date :

2025-10-27T00:00:00.000Z

Last Modified :

2025-10-27T17:36:03.062Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-61482 vulnerability.

Vendors Products
Google
  • Android
Privacyidea
  • Privacyidea
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact