CVE Alert: CVE-2025-3871

Vulnerability Summary: CVE-2025-3871
Broken access control in Fortra’s GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situation when configured to use GoAnywhere One-Time Password (GOTP) email two-factor authentication (2FA) and the user has not set an email address. In this scenario, the attacker may enter the email address of a known user when prompted and the user will be disabled if that user has configured GOTP.
Affected Endpoints:
No affected endpoints listed.
Published Date:
7/16/2025, 2:15:24 PM
⚠️ CVSS Score:
Exploit Status:
Not ExploitedReferences:
Recommended Action:
No proposed action available. Please refer to vendor documentation for updates.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below
To keep up to date follow us on the below channels.

![[RADAR] - Ransomware Victim: MC INVERSIONES INMOBILIARIAS Construction company in Peru 2 image](https://www.redpacketsecurity.com/wp-content/uploads/2024/09/image-300x300.png) 
                       
                       
