All 6 CVE vulnerabilities found in miniOrange 2FA, with AI-generated Chinese analysis, references, and POCs.
Vendor: Unknown
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-77770 | miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Email Link Validator | - | - | 2026-09-10 |
| CVE-2026-77771 | miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout | - | - | 2026-09-10 |
| CVE-2026-16619 | miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts | 7.5 | High | 2026-08-06 |
| CVE-2026-16036 | miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding | - | - | 2026-08-05 |
| CVE-2026-16035 | miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send | - | - | 2026-08-04 |
| CVE-2026-12695 | miniOrange 2FA < 6.2.6 - 2FA Bypass via Attacker-Controlled ga_secret | - | - | 2026-07-31 |
All 6 known CVE vulnerabilities affecting miniOrange 2FA with full Chinese analysis, references, and POCs where available.