Loading vulnerability details…
CVSS v3.1
2.8
EPSS
0.14%
Published
Dec 17, 2025
Modified
Jan 5, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
There is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enumerate users by entering an OTP code and new password then reviewing application responses.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:NWeaknesses (CWE)
Affected Products (1)
References (2)