CWE-306
2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (2,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Jector Smart TV FM-K75 devices allow remote code execution because there is an adb open port with root permission. |
The Xiaomi M365 scooter 2019-02-12 before 1.5.1 allows spoofing of "suddenly accelerate" commands. This occurs because Bluetooth Low Energy commands have no server-side authentication check. Other affected commands inclu...Show more |
1Bosch 11Access Easy Controller Firmware Access Professional EditionBosch Video Client+8 moreJun 17, 2026 May 29, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Vide...Show more |
1Vstracam 2C38s Firmware C7824wip FirmwareJun 17, 2026 May 23, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in upgrade_firmware.cgi on VStarcam 100T (C7824WIP) CH-sys-48.53.75.119~123 and 200V (C38S) CH-sys-48.53.203.119~123 devices. A remote command can be executed through a system firmware update with...Show more |
2Vstarcam Vstracm2C38s Firmware C7824iwp FirmwareJun 17, 2026 May 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devices. The web service, network, and account files can be manipulated through a web UI firmware update...Show more |
1Schneider Electric 4Modicon M340 Firmware Modicon M580 FirmwareModicon Premium Firmware+1 moreJun 17, 2026 May 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a remote code execution by overwriting configuration setti...Show more |
1Schneider Electric 12Atv Imc Drive Controller Firmware Modicon Lmc058 FirmwareModicon Lmc078 Firmware+9 moreJun 17, 2026 May 22, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is...Show more |
1Siemens 2Simatic Pcs 7 Simatic WinccJun 17, 2026 May 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 and newer (All versions), SIMATIC WinCC V7.2 and earlier (All versions), SIMATIC WinCC V7.3 and newer (All versions...Show more |
1Siemens 1Logo!8 Bm Firmware Jun 17, 2026 May 14, 2019 N/A· v4 9.4 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Attackers with access to port 10005/tcp could perform device reconfigurations and obtain project files from the devices. Th...Show more |
Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to retrieve the GUI password hashes of GUI users. This vulnerability can be exp...Show more |
1Lg 3Gamp 7100 Firmware Gapm 7200 FirmwareGapm 8000 FirmwareJun 17, 2026 May 13, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing its full pathname, such as http://192.168.0.1/var/gapm7100_${today's_d...Show more |
1Wincofireworks 1Fw 1007 Firmware Jun 17, 2026 May 8, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An attacker can connect to the device to trigger this vulnerability. |
1Coship 4Rt3050 Firmware Rt3052 FirmwareRt7620 Firmware+1 moreJun 17, 2026 May 7, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST request to the regx/wirel...Show more |
1Fujifilm 3Cr Ir 357 Fcr Capsula X Firmware Cr Ir 357 Fcr Carbon X FirmwareCr Ir 357 Fcr Xc 2 FirmwareJun 17, 2026 Apr 30, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure telnet services that lack authentication requirements. An attacker who succ...Show more |
1Tibco 5Activematrix Bpm Activematrix Policy DirectorActivematrix Service Bus+2 moreJun 17, 2026 Apr 24, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The administrative web server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TI...Show more |
In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfaces, without restricting registration of MBeans, which allows remote attackers to execute arbitrary c...Show more |
2Heketi Project Redhat2Heketi Openshift Container PlatformJun 17, 2026 Apr 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3....Show more |
An incorrect access control exists in the Sony Photo Sharing Plus application in the firmware before PKG6.5629 version (for the X7500D TV and other applicable TVs). This vulnerability allows an attacker to read arbitrary...Show more |
1Motorola 2Cx2 Firmware M2 FirmwareJun 17, 2026 Apr 18, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port without authentication to obtain information such as the MAC addresses of connected clie...Show more |
A vulnerability in the development shell (devshell) authentication for Cisco Aironet Series Access Points (APs) running the Cisco AP-COS operating system could allow an authenticated, local attacker to access the develop...Show more |