← Back
CWE-294

240 CVEs • Abstraction: Base • Likelihood of Exploit: High

Authentication Bypass by Capture-replay

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

JSON object

Loading...

CVEs (240)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
2P30 Firmware
P30 Pro Firmware
Jun 17, 2026
Jun 4, 2019
N/A· v4
4.2 MEDIUM· v3
4.3 MEDIUM· v2
Some Huawei 4G LTE devices, P30 versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1) and P30 Pro versions before VOG-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), are exposed to a message replay vulnerability. For th...Show more
Some Huawei 4G LTE devices, P30 versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1) and P30 Pro versions before VOG-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), are exposed to a message replay vulnerability. For the sake of better compatibility, these devices implement a less strict check on the NAS message sequence number (SN), specifically NAS COUNT. As a result, an attacker can construct a rogue base station and replay the GUTI reallocation command message in certain conditions to tamper with GUTIs, or replay the Identity request message to obtain IMSIs. (Vulnerability ID: HWPSIRT-2019-04107)Show less
1Verizon
1Fios Quantum Gateway G1100 Firmware
Jun 17, 2026
Apr 11, 2019
N/A· v4
7.5 HIGH· v3
5.4 MEDIUM· v2
Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthenticated attacker with adjacent network access to intercept and replay login req...Show more
Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthenticated attacker with adjacent network access to intercept and replay login requests to gain access to the administrative web interface.Show less
1Ysoft
1Safeq Server Client
Nov 21, 2024
Mar 21, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
YSoft SafeQ Server 6 allows a replay attack.
2Chuango
Eminent
11A11 Pstn/lcd/rfid Touch Alarm System Firmware
A8 Pstn Alarm System FirmwareAwv Plus Wifi Alarm System Firmware+8 more
Jun 17, 2026
Mar 11, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded product...Show more
The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded products, and non-Chuango branded products such as the Eminent EM8617 OV2 Wifi Alarm System.Show less
1Hetronic
5Bms Hl Firmware
Dc Mobile FirmwareEs Can Hl Firmware+2 more
Nov 21, 2024
Jan 25, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled...Show more
Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.Show less
1Zte
1Zxr10 8905e Firmware
Jun 17, 2026
Nov 1, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attackers to spoof connecti...Show more
All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attackers to spoof connections.Show less
1Sagaradio
1Saga1 L8b Firmware
Nov 21, 2024
Oct 24, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to a replay attack and command forgery.
1Telecrane
11F25 10d Firmware
F25 10s FirmwareF25 2d Firmware+8 more
Nov 21, 2024
Oct 24, 2018
N/A· v4
8.1 HIGH· v3
4.8 MEDIUM· v2
All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message,...Show more
All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.Show less
1Descor
1Infocad Fm
Nov 21, 2024
Oct 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers.
1Neatorobotics
3Botvac D4 Connected Firmware
Botvac D6 Connected FirmwareBotvac D7 Connected Firmware
Nov 21, 2024
Sep 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserve...Show more
A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. There are no nonces, and timestamps are not checked at all.Show less
1O.bike
2Obike Stationless Bike Sharing
Smart Locker Firmware
Nov 21, 2024
Sep 14, 2018
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the loc...Show more
oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol.Show less
1Schneider Electric
1Modicon M221 Firmware
Jun 17, 2026
Aug 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to replay authentic...Show more
An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to replay authentication sequences. If an attacker exploits this vulnerability and connects to a Modicon M221, the attacker can upload the original program from the PLC.Show less
1Medtronicdiabetes
9508 Minimed Insulin Pump Firmware
522 Paradigm Real Time Firmware523 Paradigm Revel Firmware+6 more
May 22, 2025
Aug 13, 2018
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wi...Show more
Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless transmissions between the remote controller and the pump and replay them to cause an insulin (bolus) delivery.Show less
3Debian
OpensuseRedhat
10Ceph
Ceph StorageCeph Storage Mon+7 more
Nov 21, 2024
Jul 10, 2018
N/A· v4
7.5 HIGH· v3
5.4 MEDIUM· v2
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can us...Show more
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.Show less
1Insteon
1Insteon Hub Firmware
Nov 21, 2024
Feb 22, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In version 1012 and prior of Insteon's Insteon Hub, the radio transmissions used for communication between the hub and connected devices are not encrypted.
1D Link
2Dir 130 Firmware
Dir 330 Firmware
May 13, 2026
Dec 16, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate t...Show more
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate the POST request in such a manner as to access some administrator-only pages such as tools_admin.asp without credentials.Show less
1Microsoft
2Lync
Skype For Business
May 13, 2026
Oct 13, 2017
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Skype for Business in Microsoft Lync 2013 SP1 and Skype for Business 2016 allows an attacker to steal an authentication hash that can be reused elsewhere, due to how Skype for Business handles authentication requests, ak...Show more
Skype for Business in Microsoft Lync 2013 SP1 and Skype for Business 2016 allows an attacker to steal an authentication hash that can be reused elsewhere, due to how Skype for Business handles authentication requests, aka "Skype for Business Elevation of Privilege Vulnerability."Show less
1Schneider Electric
1Modbus Firmware
Jun 4, 2026
Jun 30, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker...Show more
An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker to replay the following commands: run, stop, upload, and download.Show less
1Fiyo
1Fiyo Cms
May 13, 2026
Mar 12, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action.
1Microsoft
2Exchange Server
Windows 2000
Apr 16, 2026
Mar 8, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying vi...Show more
SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.Show less