CVE-2021-41716
Critical · CVSS 9.8Maharashtra State Electricity Board Mahavitaran Android Application — OTP Fixation Account Takeover (CWE-287 Authentication Bypass)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-287
Description
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function
Search profile — drives PoC discovery
Symbols OTP fixationpassword resetaccount takeoverOTPMahavitaranMSEB
Keywords CVE-2021-41716MahavitaranMSEBOTP fixationaccount takeoverAndroidpassword reset vulnerabilityMaharashtra State Electricity Boardauthentication bypass
Versions: <= 8.20
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z