Aikaan IoT Management Platform Password Exposure Vulnerability in Activation Links

Vulnerability

A vulnerability in the Aikaan IoT management platform, specifically in version 3.25.0325-5-g2e9c59796 and earlier, allows for the exposure of initial account passwords. During the onboarding process, the platform sends activation emails containing the new password in plaintext. Additionally, this password is included as a query parameter in the activation URL. This practice can lead to password exposure through various means such as browser history, proxy logs, referrer headers, and email caching. As a result, the vulnerability compromises the confidentiality of user credentials during the onboarding phase.

Impact

Exploitation of this vulnerability allows an attacker to access the initial account password through intercepted or stored copies of the activation link, fully compromising the user's account.

Reproduction

The vulnerability can be reproduced by signing up for a new account on the Aikaan IoT management platform. After registration, the activation email will be received, which includes the password in plaintext. The same password will be embedded in the activation link as a query parameter. This link can be accessed from email, browser history, or proxy logs, exposing the password and allowing for account compromise.

Added: Aug 21, 2025, 6:20 PM
Updated: Aug 21, 2025, 8:37 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
0.0
relevance
0.4
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.