Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-13166— Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account Discovery

Quick assessment

Affected
WSO2 WSO2 Identity Server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在短信一次性密码(OTP)验证流程中,错误消息的处理不够完善,使得攻击者能够根据发起 OTP 流程时收到的响应,推断出哪些用户账号是已注册的。 该弱点可被攻击者利用来发现系统内有效的用户名。对于未绑定手机号码的账号,这种枚举效应尤为明显,因为该漏洞与“未配置手机号”这一条件直接相关。这些用户名的发现可能为后续的暴力破解攻击、社会工程学尝试和信息泄露提供便利,进而可能导致声誉受损、客户信任度下降以及不符合监管合规要求。

CVSS 3.7 · Low

Possible ATT&CK Techniques 1 AI

T1079
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-13166

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account Discovery
Source: CVE Program / CVE List V5
Vulnerability Description
The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an attacker to discover valid usernames within the system. The impact is amplified for accounts that have not configured a mobile number, as the enumeration is specifically tied to this condition. The discovery of these usernames can facilitate subsequent brute force attacks, social engineering attempts, and information leakage, potentially leading to reputational damage, loss of customer trust, and regulatory non-compliance.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过差异性导致的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WSO2 WSO2 Identity Server 7.1.0 ~ 7.1.0.40 -

II. Public POCs for CVE-2025-13166

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-13166

登录查看更多情报信息。

Vendor Advisories for CVE-2025-13166 (1)

Same Patch Batch · WSO2 · 2026-09-15 · 3 CVEs total

CVE-2026-19515 7.0 HIGH OS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Extension Allow
CVE-2025-5802 5.3 MEDIUM Username Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Acco

IV. Related Vulnerabilities

V. Comments for CVE-2025-13166

No comments yet


Leave a comment