Cyber Posture

CVE-2025-31694

High

Published: 31 March 2025

Published
31 March 2025
Modified
02 September 2025
KEV Added
Patch
CVSS Score 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0027 50.7th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.

Security Summary

CVE-2025-31694 is an Incorrect Authorization vulnerability (CWE-288) in the Drupal Two-factor Authentication (TFA) module that enables forceful browsing. This flaw affects all versions of the TFA module from 0.0.0 up to but not including 1.10.0. Published on March 31, 2025, it carries a CVSS v3.1 base score of 8.1 (High), reflecting network accessibility with high attack complexity but no privileges or user interaction required.

Remote, unauthenticated attackers can exploit this vulnerability over the network by engaging in forceful browsing to bypass authorization controls in the TFA module. Successful exploitation grants high-impact access, potentially leading to unauthorized confidentiality disclosures, integrity modifications, and availability disruptions within affected Drupal sites using vulnerable TFA versions.

The Drupal Security Advisory SA-CONTRIB-2025-023 at https://www.drupal.org/sa-contrib-2025-023 details mitigation steps, with the fix implemented in TFA version 1.10.0; administrators should upgrade to this or later versions to remediate the issue.

Details

CWE(s)
CWE-288

Affected Products

two-factor authentication project
two-factor authentication
≤ 8.x-1.10

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

CVE-2025-31694 is an access bypass vulnerability in Drupal's Two-factor Authentication module via forceful browsing of overridden login routes, enabling exploitation of a public-facing web application.

References