CVE-2025-2910

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 28, 2025
CWE ID 121

Summary

CVE-2025-2910 is a vulnerability in the MeetMe authentication service's password reset module. Before version 2024-09, this service allowed attackers to enumerate user accounts by observing specific error messages, revealing whether an email address is registered or not. This issue poses a significant risk as it can aid attackers in targeted phishing or brute-force attacks, potentially leading to unauthorized access. Organizations using the MeetMe authentication service are advised to upgrade to the latest version as soon as possible to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share