Image
Dot. Manual
Image
Dot. Manual
Back to home

Dot.

Install Dot. AppDiagnostic Tool

Quote

Quote/0New
Pairing Quote/0How to TapShare with Family and FriendsHow to Charge
Content Mode
Loop ContentFixed Content
TimingNewApp Clip and Tap-to-InteractNew
Screen States and Troubleshooting
Update DeviceReset NetworkReset DeviceChangelogNew
Service and RepairCustomize Quote/0

Rand

Rand/0New
Getting StartedNew
FeaturesNew
Book of AnswersFortuneMBTI GuideWooden FishCoin FlipBluetooth RemoteNewPomodoroNewClockTimerNewDice RollNumber Under TenDisplay ModeNewNFC Cards
Wi-FiCustom WallpaperSettingsHow to Charge
Update DeviceReset DeviceChangelogNew
Service and RepairCustomize Rand/0

Read

Read PicoNew
Getting StartedNew
CrossMuxNewPico ReaderNewRickyOSNew
Demo SystemDIY Your System

Content & Services

Roadmap
Content Studio
Join Content StudioRSS
Shortcuts
Co CreateNew
SoftwareNew
Quote
Rand
ReadNew
HardwareNew
Quote
Rand
ReadNew
Open PlatformNew
What is an APIDot SkillNewGet API KeyGet Device Serial NumberGet Device ListGet Device StatusGet TimezonesNewDevice SettingsNewSwitch to Next ContentList Device ContentControl Text ContentNewControl Image ContentNewControl Canvas ContentNew

Explore More Possibilities

Request New ContentJoin Content StudioOur Repositories

Security

MSA-2025-08-001MSA-2025-09-001MSA-2025-09-002MSA-2025-10-001MSA-2025-10-002MSA-2025-10-003MSA-2026-04-001MSA-2026-10-001MSA-2026-10-002MSA-2026-10-003
Responsible Disclosure Policy

More

Service StatusService and RepairCustomize ProductsPrivacy PolicyUser AgreementContact UsAbout MindReset
SecuritySecurity Advisory
Image

MSA-2026-10-002

Insufficient verification email throttling allowed repeated sends to the same recipient

RSS

Release Date: Oct 08, 2026
Last Updated: Oct 08, 2026
Severity: Medium
Status: Fixed
CVSS 4.0 Score: 6.9 (AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N)


Overview

The verification email flow allowed unauthenticated requests to trigger repeated one-time password (OTP) emails to the same recipient without a shared recipient cooldown or hourly and daily sending limits. Existing IP-based controls did not adequately restrict this behavior.

Additional rate limits and input validation have been added to email and SMS verification requests.

Impact Scope

ItemDetails
Affected ProductDot Server-side authentication API
Affected VersionVerification email flow before the server-side fix
Fixed VersionServer-side fix
Affected Component/api/authV2/email-otp/send-verification-otp and related OTP send flows
Attack VectorNetwork
Required PrivilegeNone (verification requests are available before sign-in)

Technical Description

The configured email-send rate-limit rule referred to a different path from the endpoint used by the login flow. There was also no shared limit on sends to a particular recipient. Requests from different IP addresses could therefore continue targeting the same mailbox.

The previous shared rate-limit storage read and updated counters in separate operations. Concurrent requests could read the same count before updating it, weakening IP-based enforcement.

Accepted resend requests generated new verification records and triggered email delivery. Verification used the newest record, so a resend could invalidate a code that the recipient was about to enter. Repeated sends could also overwhelm the recipient with unwanted messages. Requesting an OTP did not reveal the code to the requester or provide authenticated access to the recipient's account.

Potential Consequences

  • Repeated unsolicited verification emails to a targeted mailbox.
  • Increased email delivery costs and consumption of sending capacity.
  • Disruption of normal verification attempts and reduced availability of the verification flow.

Remediation

  • Added rate limits to email and SMS verification requests.
  • Improved input validation and feedback when requests are sent too frequently.

Impact Assessment

We classify this issue as Medium, with a CVSS 4.0 base score of 6.9. An unauthenticated network attacker could repeatedly invoke the verification flow without user interaction. The assessment assigns limited availability impact to the verification service (VA:L), reflecting disruption of legitimate verification and consumption of sending capacity. It does not establish confidentiality or integrity loss, account takeover, or a complete service outage.

User Action

No client update is required. When a verification request is rate-limited, wait for the indicated retry period. A rejected resend leaves the previously issued code unchanged.

Acknowledgements

We thank Shuvo Kumar Saha (Syper-shuvo) for responsibly reporting the verification email flooding issue and providing reproduction details.


Disclaimer: This advisory reflects information available at publication and will be updated if material changes occur.
Document ID: MSA-2026-10-002
Classification: Public
Issued by: MindReset Security Team

Did this solve your problem?

Join our community

MSA-2026-10-001

Missing server-side allowlist for API key prefixes

MSA-2026-10-003

Concurrent API key creation could bypass the ten-key account limit

Contents

OverviewImpact ScopeTechnical DescriptionPotential ConsequencesRemediationImpact AssessmentUser ActionAcknowledgements