Impact
Traccar servers prior to version 6.16.0 are vulnerable to a password‑recovery flaw that allows an attacker to reuse password reset tokens as full session credentials. Because the TokenManager component does not bind a token to a specific purpose, a leaked reset link can be replayed with the /api/session endpoint to obtain a session token or with the /api/password/update endpoint to change the victim’s password. This permits the attacker to gain complete control of the account for up to seven days even after the user resets the password, constituting a session‑hijacking vulnerability classified as CWE‑640.
Affected Systems
Affected systems are Traccar server installations version 6.16.0 or earlier. The issue exists in the open‑source Traccar application, specifically the API endpoints that handle password reset and session creation. Administrators should review all deployments of Traccar 6.16.0 or older to verify whether the vulnerable TokenManager is in use.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.6, indicating high severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely via the web API; no local privileges or additional vulnerabilities are required. Because password reset links are often transmitted by email or other channels, interception or accidental exposure can provide the attacker with a usable token. Once replayed, it grants persistent access for a week, creating a significant risk of unauthorized data access, configuration changes, and service disruption.
OpenCVE Enrichment