Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.8.0, from 5.2.0 before 5.2.1, from 0.0.0 before 5.0., from 0.0.0 before 5.1..
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/6xxx/CVE-2025-6675.json",
"cna_assigner": "drupal",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "0.0.0"
},
{
"fixed": "4.8.0"
},
{
"introduced": "0.0.0"
},
{
"fixed": "5.0.*"
},
{
"introduced": "0.0.0"
},
{
"fixed": "5.1.*"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-288"
]
}