CVE-2025-69614
Analyzed Analyzed - Analysis Complete
Activation Token Reuse Enables Account Takeover in Telekom Portal

Publication date: 2026-03-10

Last updated on: 2026-05-07

Assigner: MITRE

Description
Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2025-10-27, fixed 2025-10-31.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-10
Last Modified
2026-05-07
Generated
2026-06-16
AI Q&A
2026-03-10
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
telekom account_management_portal to 2025-10-27 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-640 The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2025-69614 is a critical vulnerability in the Deutsche Telekom Account Management Portal caused by incorrect access control related to activation token reuse on the password-reset endpoint.

The flaw allows previously issued or unbound activation tokens to be reused by unauthorized attackers, enabling them to reset passwords for targeted accounts without permission.

This vulnerability leads to full account takeover (ATO) by attackers exploiting the token validation mechanism.

It affected all versions of the portal before 2025-10-27 and was fixed on 2025-10-31.

Impact Analysis

This vulnerability can have severe impacts as it allows unauthorized attackers to reset passwords and take full control over user accounts.

An attacker exploiting this flaw can gain access to sensitive personal or organizational data stored within the compromised accounts.

Full account takeover can lead to identity theft, unauthorized transactions, data breaches, and further exploitation within the affected system.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

The vulnerability is caused by incorrect access control via activation token reuse on the password-reset endpoint, allowing unauthorized password resets and full account takeover.

Immediate mitigation involves updating the Deutsche Telekom AG Telekom Account Management Portal to version 2025-10-31 or later, where the issue has been fixed.

Until the update can be applied, restrict access to the password-reset endpoint and monitor for suspicious password reset activities to reduce risk.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-69614. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart