CVE-2021-44161 | Changing Information Technology Inc. MOTP(Mobile One Time Password) - SQL Injection
Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input. A attacker in local area network can perform SQL injection attack to read, modify or delete backend database without authentication.
Conclusion & alert: CVE-2021-44161 is rated Moderate Risk (46.9/100): CVSS High severity, with low exploitation likelihood (EPSS 0.16%).Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2021-44161
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).