CVE-2025-31694
Published: 31 March 2025
Description
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Security Summary
CVE-2025-31694 is an Incorrect Authorization vulnerability (CWE-288) in the Drupal Two-factor Authentication (TFA) module that enables forceful browsing. This flaw affects all versions of the TFA module from 0.0.0 up to but not including 1.10.0. Published on March 31, 2025, it carries a CVSS v3.1 base score of 8.1 (High), reflecting network accessibility with high attack complexity but no privileges or user interaction required.
Remote, unauthenticated attackers can exploit this vulnerability over the network by engaging in forceful browsing to bypass authorization controls in the TFA module. Successful exploitation grants high-impact access, potentially leading to unauthorized confidentiality disclosures, integrity modifications, and availability disruptions within affected Drupal sites using vulnerable TFA versions.
The Drupal Security Advisory SA-CONTRIB-2025-023 at https://www.drupal.org/sa-contrib-2025-023 details mitigation steps, with the fix implemented in TFA version 1.10.0; administrators should upgrade to this or later versions to remediate the issue.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
CVE-2025-31694 is an access bypass vulnerability in Drupal's Two-factor Authentication module via forceful browsing of overridden login routes, enabling exploitation of a public-facing web application.