← Back
CWE-306

2,579 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,579)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
2Ex1200t Firmware
Ex300 V2 Firmware
Jun 17, 2026
Mar 30, 2022
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.
1Totolink
1A3100r Firmware
Jul 9, 2026
Mar 30, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.
1Totolink
1A3100r Firmware
Jul 9, 2026
Mar 30, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure multiple settings without authentication.
2Redhat
Theforeman
2Foreman Ansible
Satellite
Jun 17, 2026
Mar 23, 2022
N/A· v4
8.0 HIGH· v3
6.5 MEDIUM· v2
An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is...Show more
An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less
1Bigantsoft
1Bigant Server
Jul 9, 2026
Mar 21, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.
1Garo
3Wallbox Glb Firmware
Wallbox Gtb FirmwareWallbox Gtc Firmware
Jun 17, 2026
Mar 21, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control. Lack of access control on the web manger pages allows any user to view and modify information.
1Piwigo
1Piwigo
Jun 17, 2026
Mar 18, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Mar 18, 2022
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
The GSMA authentication panel could be presented on the lock screen. The issue was resolved by requiring device unlock to interact with the GSMA authentication panel. This issue is fixed in iOS 15.4 and iPadOS 15.4. A pe...Show more
The GSMA authentication panel could be presented on the lock screen. The issue was resolved by requiring device unlock to interact with the GSMA authentication panel. This issue is fixed in iOS 15.4 and iPadOS 15.4. A person with physical access may be able to view and modify the carrier account information and settings from the lock screen.Show less
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Mar 17, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
1Netgear
3Mbr1517 Firmware
Wac104 FirmwareWnce3001 Firmware
Jun 17, 2026
Mar 17, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key informatio...Show more
A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information for the device.Show less
1Netgear
5R6220 Firmware
R6900 FirmwareR7450 Firmware+2 more
Jun 17, 2026
Mar 17, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes firmware version i...Show more
A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes firmware version information for the device.Show less
1Wavlink
1Wl Wn531g3 Firmware
Jun 17, 2026
Mar 17, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When processed, it exposes som...Show more
A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information of the manager of router.Show less
1Wavlink
1Wl Wn531g3 Firmware
Jun 17, 2026
Mar 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When an unauthorized user accesses t...Show more
A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When an unauthorized user accesses this page directly, it connects to this device as a friend of the device owner.Show less
1Ptc
2Axeda Agent
Axeda Desktop Server
Jun 17, 2026
Mar 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific port without proper authentication. Succes...Show more
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific port without proper authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to read and modify the affected product’s configuration.Show less
1Ptc
2Axeda Agent
Axeda Desktop Server
Jun 17, 2026
Mar 16, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a certain command to a specific port without authentication. Successful explo...Show more
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a certain command to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to shut down a specific service.Show less
1Ptc
2Axeda Agent
Axeda Desktop Server
Jun 17, 2026
Mar 16, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful exploitation of this vulnerability could...Show more
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to obtain full file-system access and remote code execution.Show less
1Huawei
1Atune
Jun 17, 2026
Mar 11, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate the local privilege or modify any file. Authentication is not forcibly enabled in the default confi...Show more
atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate the local privilege or modify any file. Authentication is not forcibly enabled in the default configuration.Show less
1Freetakserver Ui Project
1Freetakserver Ui
Jun 17, 2026
Mar 11, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsaf...Show more
An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users.Show less
1Mitel
2Micollab
Mivoice Business Express
Jun 17, 2026
Mar 10, 2022
N/A· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degrada...Show more
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.Show less
1Hegemonelectronics
1Plc4trucks Firmware
Jun 17, 2026
Mar 10, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Power Line Communications PLC4TRUCKS J2497 trailer brake controllers implement diagnostic functions which can be invoked by replaying J2497 messages. There is no authentication or authorization for these functions.