Improper TLS certificate validation and credential exposure in the RCDevs OpenOTP SMS connector

  • Level: High
  • CVE(s):  none
  • Affected Devices: RCDevs OpenOTP

Overview

  • Severity: High — CVSS 3.1: 7.4 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
  • CWE: CWE-295 (Improper Certificate Validation), CWE-598 (Sensitive Data in GET Request), CWE-319 (Cleartext Transmission)
  • CVE: none
  • Affected product: RCDevs OpenOTP SMS integration connector
  • Affected versions: 1.0
  • Fixed in: 1.1
  • Published: 2026-09-18

Summary

The advisory applies only to The RCDevs OpenOTP SMS plugin. The RCDevs OpenOTP SMS connector shipped with SMSEagle did not validate the TLS certificate of the remote endpoint, and transmitted the connection credentials and the message content as parameters in the request URL. An attacker in a privileged network position could intercept or tamper with this traffic.

Impact

  • Disclosure of SMSC connection credentials and of the message content (including one-time passwords).
  • Possible interception or modification of SMS traffic via a man-in-the-middle attack.

Resolution

Upgrade to latest version of RCDevs OpenOTP SMS integration connector. The fix enforces TLS certificate validation and stops transmitting credentials in the request URL.

Workaround

Until the upgrade, restrict the connector to trusted network paths and ensure the endpoint uses a valid, verifiable TLS certificate.

Credit

We thank Marish Vhia Pasco for reporting this issue in line with our responsible disclosure policy.

Timeline

  • 2026-09-15 Reported
  • 2026-09-18 Fix released / advisory published

SMSEagle Security Advisories

SMSEagle continuously monitors and reports cybersecurity threats, enabling our customers to proactively take necessary mitigation steps to maintain the security of their devices. To assist you in managing and mitigating security risks SMSEagle offers product advisories.