CWE-287
4,509 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,509)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netgear 2Wac505 Firmware Wac510 FirmwareNov 21, 2024 Apr 22, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by authentication bypass. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17. |
NETGEAR WAC510 devices before 5.0.0.17 are affected by authentication bypass. |
1Netgear 3Gs810emx Firmware Xs512em FirmwareXs724em FirmwareNov 21, 2024 Apr 22, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by authentication bypass. This affects GS810EMX before 1.0.0.5, XS512EM before 1.0.0.6, and XS724EM before 1.0.0.6. |
NETGEAR XR500 devices before 2.3.2.32 are affected by authentication bypass. |
2Abb Busch Jaeger26186/11 Firmware Tg/s3.2 FirmwareJun 17, 2026 Apr 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application without authenticating by accessing a specific uniform resource locator (U...Show more |
1Netgear 14D6100 Firmware D7000 FirmwareD7800 Firmware+11 moreNov 21, 2024 Apr 22, 2020 N/A· v4 8.4 HIGH· v3 4.6 MEDIUM· v2 Certain NETGEAR devices are affected by authentication bypass. This affects D6100 before V1.0.0.55, D7000 before V1.0.1.50, D7800 before V1.0.1.24, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, R6100 before 1.0....Show more |
1Netgear 13Ex3700 Firmware Ex3800 FirmwareEx6120 Firmware+10 moreNov 21, 2024 Apr 22, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by authentication bypass. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX6120 before 1.0.0.32, EX6130 before 1.0.0.16, R6300v2 before 1.0.4.12, R6700 before 1.0.1.26,...Show more |
In JetBrains Space through 2020-04-22, the password authentication implementation was insecure. |
In Saml2 Authentication Services for ASP.NET versions before 1.0.2, and between 2.0.0 and 2.6.0, there is a vulnerability in how tokens are validated in some cases. Saml2 tokens are usually used as bearer tokens - a call...Show more |
1Evenroute 1Iqrouter Firmware Jun 17, 2026 Apr 21, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, a...Show more |
In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-ne...Show more |
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modules. This allows one to perform administrative tasks (e.g., modify the admin password) with no authen...Show more |
1Huawei 1Taurus Al00b Firmware Jun 17, 2026 Apr 20, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Huawei smartphones Taurus-AL00B with versions earlier than 10.0.0.205(C00E201R7P2) have an improper authentication vulnerability. The software insufficiently validate the user's identity when a user wants to do certain o...Show more |
Huawei smartphones Honor V20 with versions earlier than 10.0.0.179(C636E3R4P3),versions earlier than 10.0.0.180(C185E3R3P3),versions earlier than 10.0.0.180(C432E10R3P4) have an information disclosure vulnerability. The...Show more |
1Netgear 16D6220 Firmware D6400 FirmwareD8500 Firmware+13 moreNov 21, 2024 Apr 20, 2020 N/A· v4 8.4 HIGH· v3 4.6 MEDIUM· v2 Certain NETGEAR devices are affected by authentication bypass. This affects D6220 before 1.0.0.26, D6400 before 1.0.0.60, D8500 before 1.0.3.29, R6250 before 1.0.4.12, R6400 before 1.01.24, R6400v2 before 1.0.2.30, R6700...Show more |
handleIncomingPacket in conn.go in Pion DTLS before 1.5.2 lacks a check for application data with epoch 0, which allows remote attackers to inject arbitrary unencrypted data after handshake completion. |
Authentication bypass vulnerability in MfeUpgradeTool in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 Update allows administrator users to access policy settings via running this tool. |
1Ui 2Cloud Key Gen2 Cloud Key Gen2 PlusJun 17, 2026 Apr 13, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 UniFi Cloud Key firmware < 1.1.6 contains a vulnerability that enables an attacker being able to change a device hostname by sending a malicious API request. This affects Cloud Key gen2 and Cloud Key gen2 Plus. |
1Huawei 2Mate 30 Firmware Mate 30 Pro FirmwareJun 17, 2026 Apr 10, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There is an improper authentication vulnerability in several smartphones. Certain function interface in the system does not sufficiently validate the caller's identity in certain share scenario, successful exploit could...Show more |
As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicio...Show more |