CVE-2026-7671 affects CodeWise Tornet Scooter Mobile App version 4.75 on iOS and Android. According to the provided information, the vulnerable component is an unspecified function associated with the /TwoFactor file or endpoint. The flaw allows manipulation that results in improper restriction of excessive authentication attempts, indicating that the two-factor authentication mechanism does not adequately limit repeated authentication guesses or retries. The issue is remotely exploitable, but the available information states that exploitation is highly complex and difficult. No further technical details about the exact function, request flow, or validation logic are currently available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-7671, affecting Tornet Scooter Mobile App 4.75 on Android. The repo contains only two files: a README describing the vulnerability and disclosure timeline, and poc.py implementing the exploit logic. The vulnerability is an OTP brute-force condition caused by missing rate limiting or lockout on the documented /TwoFactor verification endpoint. The exploit is operational rather than a mere detector: it sends concurrent HTTP POST requests using the requests library and a ThreadPoolExecutor with 30 worker threads. For each candidate 4-digit code, it builds a JSON body containing PhoneNumber, Country, CountryCode, and VerificationCode, then submits it to a user-supplied URL. The script currently leaves the URL blank, so the operator must populate the actual endpoint before execution. It brute-forces codes in the range 5000-9998, not the full 0000-9999 space claimed in the README, suggesting the PoC is a partial search example or tuned for a known subset. Success is determined by parsing the JSON response and checking whether the field message equals "Home". When that occurs, the script records the successful OTP, sets a global stop flag, prints the result, and logs it. All attempts and responses are written to a local file named log.log. The code does not include post-exploitation, shell access, persistence, or arbitrary command execution; its sole capability is unauthorized OTP recovery via online brute force against a vulnerable backend API. Notable fingerprintable artifacts include the documented /TwoFactor path, the Host header value m2.titanware.org, the local log file log.log, and the hardcoded request metadata for a Turkish phone number context. Overall, this is a focused web/network attack PoC demonstrating remote abuse of weak authentication controls in a mobile app backend.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.