Impact
Rodauth before version 2.47.0 has a vulnerability in its one-time password implementation that does not record the timestamp of the last accepted code. An attacker who observes a valid TOTP can replay it while it remains within the acceptable drift window, allowing the attacker to bypass the second authentication factor and gain unauthorized access to the system. The weakness is listed as CWE-294.
Affected Systems
The affected vendor is Jeremie Evans, product Rodauth. Versions older than 2.47.0 are impacted; the patch releases 2.47.0 or newer resolve the issue.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. EPSS information is not available and the vulnerability is not in CISA's KEV catalog. The attack can be carried out remotely as long as an adversary can observe a valid TOTP code, which may happen over network egress or by compromising a device. No additional exploitation prerequisites are noted. Given the moderate CVSS and lack of EPSS data, the risk remains moderate but should be addressed promptly.
OpenCVE Enrichment