Mahadiscom's vulnerability footprint centers on its Mahavitaran power-distribution platform, a utility-sector application managing consumer billing and account services where exposure clusters consistently around authentication and credential-handling weaknesses. The recurring signals—improper authentication, insufficient session expiration, hard-coded or insufficiently protected credentials, and exposure of sensitive information—reflect the authentication-critical role of utility customer portals and the sensitivity of personally identifiable and billing data they hold. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mahadiscom over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41716CRITICAL Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest functi | Dec 7, 2021 | 9.8 | 32 | NO | NO |
CVE-2020-27416CRITICAL Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to control a users account. | Dec 8, 2021 | 9.8 | 24 | NO | NO |
CVE-2020-27413MEDIUM An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext username and password while the user is logged into the applicat | Dec 7, 2021 | 4.2 | 20 | NO | NO |
CVE-2020-27414MEDIUM Mahavitaran android application 7.50 and prior transmit sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the | Dec 2, 2021 | 5.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mahadiscom.
Media articles that mention a CVE ID that affects a product developed by Mahadiscom — matched by CVE ID, not by vendor name.