← Back
CWE-287

4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Changjia Property Management System Project
1Changjia Property Management System
Jun 17, 2026
Feb 17, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obtaining user permissions.
1Netgear
19Ac2100 Firmware
Ac2400 FirmwareAc2600 Firmware+16 more
Jun 17, 2026
Feb 12, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, an...Show more
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-11355.Show less
1Dlink
1Dap 1860 Firmware
Jun 17, 2026
Feb 12, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders. Authentication is not required to exploit this vulnerab...Show more
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the uhttpd service, which listens on TCP port 80 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the device. Was ZDI-CAN-10894.Show less
1Dlink
2Dsl 2888a Firmware
Dva 2800 Firmware
Jun 17, 2026
Feb 12, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DVA-2800 and DSL-2888A routers. Authentication is not required to exploit this vulnerability. The...Show more
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DVA-2800 and DSL-2888A routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the dhttpd service, which listens on TCP port 8008 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-10912.Show less
1Teradici
1Cloud Access Connector
Jun 17, 2026
Feb 11, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were accessible without the need to specify authentication tokens, which allowed an attacker in the ability t...Show more
Certain web application pages in the authenticated section of the Teradici Cloud Access Connector prior to v18 were accessible without the need to specify authentication tokens, which allowed an attacker in the ability to execute sensitive functions without credentials.Show less
1Dell
1Emc Powerscale Onefs
Jun 17, 2026
Feb 9, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vulnerability. A user on the network with the ISI_PRIV_AUTH_SSH RBAC privilege that has an expired account may potentially e...Show more
Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vulnerability. A user on the network with the ISI_PRIV_AUTH_SSH RBAC privilege that has an expired account may potentially exploit this vulnerability, giving them access to the same things they had before account expiration. This may by a high privileged account and hence Dell recommends customers upgrade at the earliest opportunity.Show less
1Siemens
2Simatic Pcs 7
Simatic Wincc
Jun 17, 2026
Feb 9, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verification process, an attacker could bypass the password protection set on prot...Show more
A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verification process, an attacker could bypass the password protection set on protected files, thus being granted access to the protected content, circumventing authentication.Show less
11password
1Scim Bridge
Jun 17, 2026
Feb 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key.
1Epikur
1Epikur
Jun 17, 2026
Feb 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user login, checks the submitted password against the user password's MD5 hash stored in the database. I...Show more
An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user login, checks the submitted password against the user password's MD5 hash stored in the database. It is also compared to a second MD5 hash, which is the same for every user (aka a "Backdoor Password" of 3p1kursupport). If the submitted password matches either one, access is granted.Show less
1Apache
1Shiro
Jun 17, 2026
Feb 3, 2021
N/A· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
1Hashicorp
1Vault
Jun 17, 2026
Feb 1, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.
1Mofinetwork
1Mofi4500 4gxelte Firmware
Jun 17, 2026
Feb 1, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the ability to authenticate as root without knowing the actual root passwor...Show more
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function contains undocumented code that provides the ability to authenticate as root without knowing the actual root password. An adversary with the private key can remotely authenticate to the management interface as root.Show less
1Mofinetwork
1Mofi4500 4gxelte Firmware
Jun 17, 2026
Feb 1, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the undocumented system...Show more
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the undocumented system account mofidev to login to the cgi-bin/luci/quick/wizard management interface without a password by abusing a forgotten-password feature.Show less
1Zivautomation
14cct Ea6 334126bf Firmware
Jun 17, 2026
Jan 29, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Improper Authentication vulnerability in the cookie parameter of ZIV AUTOMATION 4CCT-EA6-334126BF allows a local attacker to perform modifications in several parameters of the affected device as an authenticated user.
4Apache
DebianNetapp+1 more
9Activemq
Activemq ArtemisArtemis+6 more
Jun 17, 2026
Jan 27, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.1...Show more
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.Show less
1Zyxel
1Nbg2105 Firmware
Jun 17, 2026
Jan 26, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.
1Open5gs
1Open5gs
Jun 17, 2026
Jan 26, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.
1Projectsend
1Projectsend
Jul 9, 2026
Jan 26, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).
1Ibm
2Spectrum Lsf
Spectrum Lsf Suite
Jun 17, 2026
Jan 20, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to submit LSF jobs to execute arbitrary commands. IBM X-Force ID: 192586.
1Sooil
3Anydana A Firmware
Anydana I FirmwareDiabecare Rs Firmware
Jun 17, 2026
Jan 19, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to b...Show more
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to bypass user authentication checks via Bluetooth Low Energy.Show less