目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-13166— WSO2 Identity Server 用户名枚举漏洞

一分钟漏洞结论

影响对象
WSO2 WSO2 Identity Server
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在短信一次性密码(OTP)验证流程中,错误消息的处理不够完善,使得攻击者能够根据发起 OTP 流程时收到的响应,推断出哪些用户账号是已注册的。 该弱点可被攻击者利用来发现系统内有效的用户名。对于未绑定手机号码的账号,这种枚举效应尤为明显,因为该漏洞与“未配置手机号”这一条件直接相关。这些用户名的发现可能为后续的暴力破解攻击、社会工程学尝试和信息泄露提供便利,进而可能导致声誉受损、客户信任度下降以及不符合监管合规要求。

CVSS 3.7 · Low

可能的 ATT&CK 技术 1 AI

T1079
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2025-13166 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account Discovery
来源: CVE Program / CVE List V5
Vulnerability Description
The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an attacker to discover valid usernames within the system. The impact is amplified for accounts that have not configured a mobile number, as the enumeration is specifically tied to this condition. The discovery of these usernames can facilitate subsequent brute force attacks, social engineering attempts, and information leakage, potentially leading to reputational damage, loss of customer trust, and regulatory non-compliance.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
通过差异性导致的信息暴露
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
WSO2 WSO2 Identity Server 7.1.0 ~ 7.1.0.40 -

二、漏洞 CVE-2025-13166 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-13166 的情报信息

登录查看更多情报信息。

CVE-2025-13166 厂商安全公告 (1)

同批安全公告 · WSO2 · 2026-09-15 · 共 3 条

CVE-2026-19515 7.0 HIGH WSO2 Integrator MI VS Code 扩展命令注入
CVE-2025-5802 5.3 MEDIUM WSO2产品注册流程用户名枚举漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-13166

暂无评论


发表评论