CVE-2025-31676: Email TFA - Moderately critical - Access bypass - SA-CONTRIB-2025-001
Published Mar 31, 2025
·Updated
Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3.
Affected Software
2 affected components
Drupal Email TFA<2.0.3
Email Tfa Project Email Tfa Drupal<2.0.3
Event History
Mar 31, 2025
CVE Published
via MITRE·09:36 PM
Data Sourced
via MITRE·09:36 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-31676?
CVE-2025-31676 has been classified as a weak authentication vulnerability, which can lead to brute force attacks.
2
How do I fix CVE-2025-31676?
To fix CVE-2025-31676, you should upgrade Drupal Email TFA to version 2.0.3 or later.
3
Which versions of Drupal Email TFA are affected by CVE-2025-31676?
CVE-2025-31676 affects all versions of Drupal Email TFA prior to 2.0.3.
4
What impact does CVE-2025-31676 have on my Drupal site?
CVE-2025-31676 allows attackers to perform brute force attacks, potentially compromising user accounts on your Drupal site.
5
Is there a workaround for CVE-2025-31676 if I cannot upgrade?
There are no specific workarounds for CVE-2025-31676; upgrading to a fixed version is the recommended solution.