CWE-306
2,579 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,579)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Totolink 2Ex1200t Firmware Ex300 V2 FirmwareJun 17, 2026 Mar 30, 2022 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism. |
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies. |
In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure multiple settings without authentication. |
2Redhat Theforeman2Foreman Ansible SatelliteJun 17, 2026 Mar 23, 2022 N/A· v4 8.0 HIGH· v3 6.5 MEDIUM· v2 An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is...Show more |
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control. |
1Garo 3Wallbox Glb Firmware Wallbox Gtb FirmwareWallbox Gtc FirmwareJun 17, 2026 Mar 21, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control. Lack of access control on the web manger pages allows any user to view and modify information. |
Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php. |
The GSMA authentication panel could be presented on the lock screen. The issue was resolved by requiring device unlock to interact with the GSMA authentication panel. This issue is fixed in iOS 15.4 and iPadOS 15.4. A pe...Show more |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Mar 17, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2). |
1Netgear 3Mbr1517 Firmware Wac104 FirmwareWnce3001 FirmwareJun 17, 2026 Mar 17, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key informatio...Show more |
1Netgear 5R6220 Firmware R6900 FirmwareR7450 Firmware+2 moreJun 17, 2026 Mar 17, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes firmware version i...Show more |
A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When processed, it exposes som...Show more |
1Wavlink 1Wl Wn531g3 Firmware Jun 17, 2026 Mar 17, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When an unauthorized user accesses t...Show more |
1Ptc 2Axeda Agent Axeda Desktop ServerJun 17, 2026 Mar 16, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific port without proper authentication. Succes...Show more |
1Ptc 2Axeda Agent Axeda Desktop ServerJun 17, 2026 Mar 16, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a certain command to a specific port without authentication. Successful explo...Show more |
1Ptc 2Axeda Agent Axeda Desktop ServerJun 17, 2026 Mar 16, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful exploitation of this vulnerability could...Show more |
atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate the local privilege or modify any file. Authentication is not forcibly enabled in the default confi...Show more |
1Freetakserver Ui Project 1Freetakserver Ui Jun 17, 2026 Mar 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsaf...Show more |
1Mitel 2Micollab Mivoice Business ExpressJun 17, 2026 Mar 10, 2022 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degrada...Show more |
1Hegemonelectronics 1Plc4trucks Firmware Jun 17, 2026 Mar 10, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Power Line Communications PLC4TRUCKS J2497 trailer brake controllers implement diagnostic functions which can be invoked by replaying J2497 messages. There is no authentication or authorization for these functions. |