Executive brief
Akinsoft LimonDesk, a customer support and help desk software, contains a security flaw that fails to limit the number of login attempts. This allows an attacker to repeatedly guess passwords until they gain unauthorized access to the system. Successful exploitation could lead to the exposure of sensitive customer data and unauthorized control over support operations.
Technical details
The vulnerability is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts) within the Akinsoft LimonDesk application. The software fails to implement adequate rate-limiting or account lockout mechanisms on its authentication interface. A remote, unauthenticated attacker can exploit this by performing brute-force or credential stuffing attacks to bypass authentication. This issue affects versions starting from s1.02.14 and was addressed in version v1.02.17.
Affected products
- Akinsoft LimonDesk from s1.02.14 before v1.02.17
Timeline
- 2025-09-03: advisory: Initial publication of the vulnerability details.
- 2025-09-03: disclosed: Vulnerability disclosed by the Computer Emergency Response Team of the Republic of Turkey.