← Back
CWE-287

4,777 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,777)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sun
1Solaris
Apr 23, 2026
Mar 17, 2008
N/A· v4
N/A· v3
6.3 MEDIUM· v2
Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using the GNOME On-Screen Keyboard (GOK), allows local users to bypass authentication via unknown vectors that cause the screen...Show more
Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using the GNOME On-Screen Keyboard (GOK), allows local users to bypass authentication via unknown vectors that cause the screen saver to crash.Show less
1Bt
1Home Hub
Apr 23, 2026
Mar 13, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
cgi/b on the BT Home Hub router allows remote attackers to bypass authentication, and read or modify administrative settings or make arbitrary VoIP telephone calls, by placing a character at the end of the PATH_INFO, as...Show more
cgi/b on the BT Home Hub router allows remote attackers to bypass authentication, and read or modify administrative settings or make arbitrary VoIP telephone calls, by placing a character at the end of the PATH_INFO, as demonstrated by (1) %5C (encoded backslash), (2) '%' (percent), and (3) '~' (tilde). NOTE: the '/' (slash) vector is already covered by CVE-2007-5383.Show less
1Gallarific
1Gallarific
Apr 23, 2026
Mar 13, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and edit tasks via a direct request. NOTE: the provenance of this information is unknown; the details...Show more
Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and edit tasks via a direct request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Asg Sentry
1Asg Sentry
Apr 23, 2026
Mar 13, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote attackers to cause a denial of service (service termination) via the exit command to TCP port 6162, or...Show more
The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote attackers to cause a denial of service (service termination) via the exit command to TCP port 6162, or have other impacts via other commands.Show less
1Alice
1Gate2 Plus Wi Fi
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
7.1 HIGH· v2
cp06_wifi_m_nocifr.cgi in the admin panel on the Alice Gate 2 Plus Wi-Fi router does not verify authentication credentials, which allows remote attackers to disable Wi-Fi encryption via a certain request.
1Linksys
1Wrt54g
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
The FTP server on the Linksys WRT54G 7 router with 7.00.1 firmware does not verify authentication credentials, which allows remote attackers to establish an FTP session by sending an arbitrary username and password.
1Linksys
1Wrt54g
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
The Linksys WRT54G router has "admin" as its default FTP password, which allows remote attackers to access sensitive files including nvram.cfg, a file that lists all HTML documents, and an ELF executable file.
1Airspan
1Wimax Prost
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote attackers to (1) upload malformed firmware or (2) bind the antenna to...Show more
The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote attackers to (1) upload malformed firmware or (2) bind the antenna to a different WiMAX base station via unspecified requests to forms under process_adv/.Show less
1Zyxel
1P 2602hw D1a
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a user wh...Show more
The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a user who previously authenticated within the previous 5 minutes.Show less
1Belkin
1F5d7230 4
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform administrative actions, as demonstrated by changing a DNS server via th...Show more
cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform administrative actions, as demonstrated by changing a DNS server via the dns1_1, dns1_2, dns1_3, and dns1_4 parameters. NOTE: it was later reported that F5D7632-4V6 with firmware 6.01.08 is also affected.Show less
1Omegasoft
1Interneserviceslosungen
Apr 23, 2026
Mar 4, 2008
N/A· v4
N/A· v3
6.4 MEDIUM· v2
OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret, which allows remote attackers to login as an arbitrary user via a modified cookie.
1Ibm
1Websphere Mq
Apr 23, 2026
Mar 4, 2008
N/A· v4
N/A· v3
6.6 MEDIUM· v2
Unspecified vulnerability in IBM WebSphere MQ 6.0.x before 6.0.2.2 and 5.3 before Fix Pack 14 allows attackers to bypass access restrictions for a queue manager via a SVRCONN (MQ client) channel.
1Bea
1Weblogic Server
Apr 23, 2026
Feb 22, 2008
N/A· v4
N/A· v3
6.4 MEDIUM· v2
BEA WebLogic Server and WebLogic Express 6.1 through 10.0 allows remote attackers to bypass authentication for application servlets via crafted request headers.
1Drupal
1Header Image
Apr 23, 2026
Feb 19, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the Header Image Module before 5.x-1.1 for Drupal allows remote attackers to access the administration pages via unknown attack vectors.
1Symantec
1Ghost Solutions Suite
Apr 23, 2026
Feb 8, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via...Show more
Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing.Show less
1Manageengine
1Applications Manager
Apr 23, 2026
Jan 29, 2008
N/A· v4
N/A· v3
6.4 MEDIUM· v2
ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote attackers to obtain sensitive information and change settings via unspeci...Show more
ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote attackers to obtain sensitive information and change settings via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Webwiz
3Web Wiz Forums
Web Wiz NewspadWeb Wiz Rich Text Editor
Apr 23, 2026
Jan 29, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files....Show more
Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a separate directory traversal vulnerability.Show less
1Hfs
1Http File Server
Apr 23, 2026
Jan 29, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as <id>%version%</id> in HTTP Basic Authentication instead of a username and password, as d...Show more
HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as <id>%version%</id> in HTTP Basic Authentication instead of a username and password, as demonstrated by placing this id element in the userinfo subcomponent of a URL.Show less
1Hfs
1Http File Server
Apr 23, 2026
Jan 29, 2008
N/A· v4
N/A· v3
6.4 MEDIUM· v2
HTTP File Server (HFS) before 2.2c allows remote attackers to append arbitrary text to the log file by using the base64 representation of this text during HTTP Basic Authentication.
1Hfs
1Http File Server
Apr 23, 2026
Jan 29, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administ...Show more
HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administrator to determine who made a remote request.Show less