← Back
CWE-306

2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,554)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Belkin
1Wemo Switch 28b Firmware
Jun 17, 2026
Oct 12, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDbBody element in a St...Show more
An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDbBody element in a StoreRules request to the upnp/control/rules1 URI, because database corruption occurs.Show less
1Dlink
2Dir 817lw A1 Firmware
Dir 868l B1 Firmware
Jun 17, 2026
Oct 11, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCO...Show more
There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used to control the router remotely.Show less
1Dlink
1Dap 1320 A2 Firmware
Jun 17, 2026
Oct 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink_info.xml. An attacker can remotely obtain a user's Wi-Fi SSID and password, which could be used to...Show more
D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink_info.xml. An attacker can remotely obtain a user's Wi-Fi SSID and password, which could be used to connect to Wi-Fi or perform a dictionary attack.Show less
1Cobham
1Explorer 710 Firmware
Jun 17, 2026
Oct 10, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This could allow an unauthenticated, local attacker connected to the device to access the portal and to make...Show more
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This could allow an unauthenticated, local attacker connected to the device to access the portal and to make any change to the device.Show less
1Zingbox
1Inspector
Jun 17, 2026
Oct 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A security vulnerability exists in the Zingbox Inspector versions 1.280 and earlier, where authentication is not required when binding the Inspector instance to a different customer tenant.
1Zyxel
1Nbg 418n V2 Firmware
Jun 17, 2026
Oct 9, 2019
N/A· v4
9.4 CRITICAL· v3
7.5 HIGH· v2
wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker...Show more
wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify data fields of the page.Show less
1Dlink
1Dir 615 Firmware
Jun 17, 2026
Oct 9, 2019
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be lev...Show more
An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.Show less
1Sap
1Process Integration
Jun 17, 2026
Oct 8, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC), leading to Missing Authenticatio...Show more
SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC), leading to Missing Authentication CheckShow less
1Fiberhome
1Hg2201t Firmware
Jun 17, 2026
Oct 8, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
/var/WEB-GUI/cgi-bin/telnet.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication remote code execution.
1Etoilewebdesign
1Ultimate Faq
Jun 17, 2026
Oct 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
1Vzug
1Combi Stream Mslq Firmware
Jun 17, 2026
Oct 6, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the device does not enforce any authentication. An adjacent attacker is able to use the network interface wit...Show more
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the device does not enforce any authentication. An adjacent attacker is able to use the network interface without proper access control.Show less
1Online Store System Project
1Online Store System
Jun 17, 2026
Oct 1, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowing arbitrary product deletion.
1Govicture
1Pc530 Firmware
Jun 17, 2026
Oct 1, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Victure PC530 devices allow unauthenticated TELNET access as root.
1Honeywell
59H2w2pc1m Firmware
H2w2per3 FirmwareH2w4per3 Firmware+56 more
Jun 17, 2026
Sep 26, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Vi...Show more
In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without authentication over the network. Affected performance IP Cameras: HBD3PR2,H4D3PRV3,HED3PR3,H4D3PRV2,HBD3PR1,H4W8PR2,HBW8PR2,H2W2PC1M,H2W4PER3,H2W2PER3,HEW2PER3,HEW4PER3B,HBW2PER1,HEW4PER2,HEW4PER2B,HEW2PER2,H4W2PER2,HBW2PER2,H4W2PER3, and HPW2P1. Affected Performance Series NVRs: HEN08104,HEN08144,HEN081124,HEN16104,HEN16144,HEN16184,HEN16204,HEN162244,HEN16284,HEN16304,HEN16384,HEN32104,HEN321124,HEN32204,HEN32284,HEN322164,HEN32304, HEN32384,HEN323164,HEN64204,HEN64304,HEN643164,HEN643324,HEN643484,HEN04103,HEN04113,HEN04123,HEN08103,HEN08113,HEN08123,HEN08143,HEN16103,HEN16123,HEN16143,HEN16163,HEN04103L,HEN08103L,HEN16103L,HEN32103L.Show less
1Gigastone
1Smart Battery A4 Firmware
Jun 17, 2026
Sep 25, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/reset administrator’s password without any authentication.
1F5
1Big Iq Centralized Management
Jun 17, 2026
Sep 25, 2019
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Layer Security (TLS).
1Netapp
1Ontap Select Deploy Administration Utility
Jun 17, 2026
Sep 24, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote attackers to perform administrative actions.
1Publisure
1Publisure
Jun 17, 2026
Sep 18, 2019
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
An issue was discovered in servletcontroller in the secure portal in Publisure 2.1.2. One can bypass authentication and perform a query on PHP forms within the /AdminDir folder that should be restricted.
1Eq 3
2Homematic Ccu2 Firmware
Homematic Ccu3 Firmware
Jun 17, 2026
Sep 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface via an HTTP POST request to certain URLs related to the ReGa core proce...Show more
eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface via an HTTP POST request to certain URLs related to the ReGa core process.Show less
1Atlassian
1Jira
Jun 17, 2026
Sep 11, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.