← Back
CWE-294

270 CVEs • Abstraction: Base • Likelihood of Exploit: High

Authentication Bypass by Capture-replay

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

JSON object

Loading...

CVEs (270)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Honeywell
1Notifier Webserver
Jun 17, 2026
Mar 24, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay attack from a web browser.
1Honda
1Hr V 2017 Firmware
Jun 17, 2026
Mar 23, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The remote keyless system on Honda HR-V 2017 vehicles sends the same RF signal for each door-open request, which might allow a replay attack.
1Yubico
1Yubikey One Time Password Validation Server
Jun 17, 2026
Mar 5, 2020
N/A· v4
8.6 HIGH· v3
6.8 MEDIUM· v2
The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service wit...Show more
The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service with a non-default configuration such as an open sync pool; the issue does NOT affect YubiCloud.Show less
1Veraxsystems
1Network Management System
Nov 21, 2024
Jan 30, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Verax NMS prior to 2.10 allows authentication via the encrypted password without knowing the cleartext password.
1Omron
2Plc Cj Firmware
Plc Cs Firmware
Jun 17, 2026
Dec 16, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of indust...Show more
In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of industrial valves.Show less
1Anviz
1Management System
Jun 17, 2026
Dec 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Anviz access control devices are vulnerable to replay attacks which could allow attackers to intercept and replay open door requests.
1Honeywell
64H2w2gr1 Firmware
H2w2pc1m FirmwareH2w2per3 Firmware+61 more
Jun 17, 2026
Oct 31, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication...Show more
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained for compatibility with legacy products.Show less
1Keyidentity
1Linotp
Jun 17, 2026
Jun 27, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
KeyIdentity LinOTP before 2.10.5.3 has Incorrect Access Control (issue 1 of 2).
1Tzumi
2Klic Lock
Klic Smart Padlock Model 5686 Firmware
Jun 17, 2026
Jun 11, 2019
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
An authentication bypass in website post requests in the Tzumi Electronics Klic Lock application 1.0.9 for mobile devices allows attackers to access resources (that are not otherwise accessible without proper authenticat...Show more
An authentication bypass in website post requests in the Tzumi Electronics Klic Lock application 1.0.9 for mobile devices allows attackers to access resources (that are not otherwise accessible without proper authentication) via capture-replay. Physically proximate attackers can use this information to unlock unauthorized Tzumi Electronics Klic Smart Padlock Model 5686 Firmware 6.2.Show less
1Gemalto
1Ezio Ds3 Server
Jun 17, 2026
Jun 5, 2019
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
Gemalto DS3 Authentication Server 2.6.1-SP01 has Broken Access Control.
1Huawei
2P30 Firmware
P30 Pro Firmware
Jun 17, 2026
Jun 4, 2019
N/A· v4
4.2 MEDIUM· v3
4.3 MEDIUM· v2
Some Huawei 4G LTE devices, P30 versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1) and P30 Pro versions before VOG-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), are exposed to a message replay vulnerability. For th...Show more
Some Huawei 4G LTE devices, P30 versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1) and P30 Pro versions before VOG-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), are exposed to a message replay vulnerability. For the sake of better compatibility, these devices implement a less strict check on the NAS message sequence number (SN), specifically NAS COUNT. As a result, an attacker can construct a rogue base station and replay the GUTI reallocation command message in certain conditions to tamper with GUTIs, or replay the Identity request message to obtain IMSIs. (Vulnerability ID: HWPSIRT-2019-04107)Show less
1Verizon
1Fios Quantum Gateway G1100 Firmware
Jun 17, 2026
Apr 11, 2019
N/A· v4
7.5 HIGH· v3
5.4 MEDIUM· v2
Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthenticated attacker with adjacent network access to intercept and replay login req...Show more
Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthenticated attacker with adjacent network access to intercept and replay login requests to gain access to the administrative web interface.Show less
1Ysoft
1Safeq Server Client
Nov 21, 2024
Mar 21, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
YSoft SafeQ Server 6 allows a replay attack.
2Chuango
Eminent
11A11 Pstn/lcd/rfid Touch Alarm System Firmware
A8 Pstn Alarm System FirmwareAwv Plus Wifi Alarm System Firmware+8 more
Jun 17, 2026
Mar 11, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded product...Show more
The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded products, and non-Chuango branded products such as the Eminent EM8617 OV2 Wifi Alarm System.Show less
1Hetronic
5Bms Hl Firmware
Dc Mobile FirmwareEs Can Hl Firmware+2 more
Nov 21, 2024
Jan 25, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled...Show more
Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.Show less
1Zte
1Zxr10 8905e Firmware
Jun 17, 2026
Nov 1, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attackers to spoof connecti...Show more
All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attackers to spoof connections.Show less
1Sagaradio
1Saga1 L8b Firmware
Nov 21, 2024
Oct 24, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to a replay attack and command forgery.
1Telecrane
11F25 10d Firmware
F25 10s FirmwareF25 2d Firmware+8 more
Nov 21, 2024
Oct 24, 2018
N/A· v4
8.1 HIGH· v3
4.8 MEDIUM· v2
All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message,...Show more
All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.Show less
1Descor
1Infocad Fm
Nov 21, 2024
Oct 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers.
1Neatorobotics
3Botvac D4 Connected Firmware
Botvac D6 Connected FirmwareBotvac D7 Connected Firmware
Nov 21, 2024
Sep 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserve...Show more
A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. There are no nonces, and timestamps are not checked at all.Show less