The flaw is classified as CWE-307 and resides in the authentication routes. The POST /api/tokens flow accepts identity and password material and, for a TOTP-enabled account, issues a short-lived challenge token. POST /api/tokens/2fa verifies the supplied code and returns a full token when the code is valid. The affected implementation lacks effective rate limiting on these authentication endpoints, so an unauthenticated network client can repeat guesses without an application-enforced attempt ceiling. Reachability requires the management API to be exposed to the attacker's network; the available evidence does not establish whether a reverse proxy, deployment topology, or external control adds compensating limits.