Monnit Cloud Platforms Password Reset Vulnerability Allowing Account Takeover

Vulnerability

A critical authentication vulnerability has been identified in Monnit cloud platforms (*.imonnit.com) that allows malicious actors to gain unauthorized access to user accounts. This vulnerability arises because the password reset endpoint does not properly validate the association between reset tokens and the corresponding email addresses. As a result, attackers can use valid tokens from their own accounts to reset passwords and take over accounts belonging to other users. The issue affects all users on the platform.

Impact

Exploitation of this vulnerability leads to full account takeover, allowing attackers to access victim dashboards, sensors, and account data. It also enables modification of devices, notifications, and configurations, all without any interaction from the victim.

Reproduction

To reproduce this vulnerability, an attacker must first create an account and then request a password reset for both their account and a victim's account. After receiving the reset token for their account, the attacker can use that token to reset the password for the victim's account by changing the email and username fields to match those of the victim.

Remediation

Monnit should implement proper validation to ensure that password reset tokens are only used for the email addresses they were originally issued to. Additionally, tokens should be invalidated immediately after use.

Added: Nov 26, 2025, 8:21 PM
Updated: Nov 26, 2025, 8:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
0.0
relevance
1.1
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.