← Back
CWE-306

2,554 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

JSON object

Loading...

CVEs (2,554)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Aveva
2Indusoft Web Studio
Intouch Machine Edition 2014
Jun 17, 2026
Feb 13, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could le...Show more
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine.Show less
1Kunbus
1Pr100088 Modbus Gateway Firmware
Jun 17, 2026
Feb 12, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166).
1Dlink
1Dir 823g Firmware
Jun 17, 2026
Feb 5, 2019
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to hijack the DNS service configuration of all clients in the WLAN, wi...Show more
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to hijack the DNS service configuration of all clients in the WLAN, without authentication, via the SetWanSettings HNAP API.Show less
1Dlink
1Dir 823g Firmware
Jun 17, 2026
Feb 5, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with the firmware 1.02B03. There is incorrect access control allowing remote attackers to reset the router without authentication via the SetFactoryDefau...Show more
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with the firmware 1.02B03. There is incorrect access control allowing remote attackers to reset the router without authentication via the SetFactoryDefault HNAP API. Consequently, an attacker can achieve a denial-of-service attack without authentication.Show less
1Estrongs
1Es File Explorer File Manager
Jun 17, 2026
Jan 16, 2019
N/A· v4
8.1 HIGH· v3
4.8 MEDIUM· v2
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port re...Show more
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP.Show less
1Cisco
1Policy Suite For Mobile
Nov 21, 2024
Jan 11, 2019
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface. The attacke...Show more
A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface. The attacker would need to have access to the internal VLAN where CPS is deployed. The vulnerability is due to lack of authentication. An attacker could exploit this vulnerability by directly connecting to the Graphite web interface. An exploit could allow the attacker to access various statistics and Key Performance Indicators (KPIs) regarding the Cisco Policy Suite environment.Show less
1Cisco
2Cisco Policy Suite Diameter Routing Agent
Cisco Policy Suite For Mobile
Nov 21, 2024
Jan 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent software could allow an unauthenticated, remote attacker to modify key-value pairs for s...Show more
A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent software could allow an unauthenticated, remote attacker to modify key-value pairs for short-lived events stored by the Redis server. The vulnerability is due to improper authentication when accessing the Redis server. An unauthenticated attacker could exploit this vulnerability by modifying key-value pairs stored within the Redis server database. An exploit could allow the attacker to reduce the efficiency of the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent software.Show less
1Sap
1Cloud Connector
Jun 17, 2026
Jan 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require user identity.
1Abb
2Gate E1 Firmware
Gate E2 Firmware
Nov 21, 2024
Jan 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet or web interfaces, which could enable various effects vectors, includin...Show more
Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet or web interfaces, which could enable various effects vectors, including conducting device resets, reading or modifying registers, and changing configuration settings such as IP addresses.Show less
1Kubernetes
1Dashboard
Nov 21, 2024
Jan 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.
1Epson
1Epson Workforce Wf 2861 Firmware
Nov 21, 2024
Dec 24, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote attackers to upload a firmware file and reset the printer without authenticatio...Show more
The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote attackers to upload a firmware file and reset the printer without authentication by making a request to the /DOWN/FIRMWAREUPDATE/ROM1 URI and a POST request to the /FIRMWAREUPDATE URI.Show less
1Rockwellautomation
161756 En2f Series A Firmware
1756 En2f Series B Firmware1756 En2f Series C Firmware+13 more
Jun 3, 2026
Dec 7, 2018
N/A· v4
8.6 HIGH· v3
7.8 HIGH· v2
Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connecti...Show more
Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connection, send a new IP configuration to the affected device even if the controller in the system is set to Hard RUN mode. When the affected device accepts this new IP configuration, a loss of communication occurs between the device and the rest of the system as the system traffic is still attempting to communicate with the device via the overwritten IP address.Show less
1Philips
2Intellispace Pacs
Isite Pacs
Nov 21, 2024
Nov 19, 2018
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of...Show more
Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of the system.Show less
1Zte
1Zxhn H168n Firmware
Jun 17, 2026
Nov 14, 2018
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, which may allow an unauthorized user to gain unauthorized access.
2Foscam
Opticam
4C2 Application Firmware
C2 System FirmwareI5 Application Firmware+1 more
Nov 21, 2024
Nov 7, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SystemReboot method allows unauthenticated reboot.
1Keruigroup
1Ypc99 Firmware
Nov 21, 2024
Oct 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow an attacker to execute arbitrary commands (with a length limit of 19 characters) via the "ssid" value, as demonstrated by...Show more
Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow an attacker to execute arbitrary commands (with a length limit of 19 characters) via the "ssid" value, as demonstrated by ssid:;ping 192.168.1.2 in the body of a SETSSID command.Show less
1Ibm
1Security Key Lifecycle Manager
Nov 21, 2024
Oct 11, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to missing authentication. IBM X-Force ID: 148424.
3Debian
StarwindsoftwareTinc Vpn
3Debian Linux
Starwind Virtual SanTinc
Nov 21, 2024
Oct 10, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.
1D Link
1Dir 823g Firmware
Nov 21, 2024
Oct 3, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 RunReboot commands without authentication to trigger a reboot.
1Tp Link
1Eap Controller
Jun 17, 2026
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation (RMI) service for remote control. The RMI interface does not require an...Show more
The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation (RMI) service for remote control. The RMI interface does not require any authentication before use, so it lacks user authentication for RMI service commands in EAP controller versions 2.5.3 and earlier. Remote attackers can implement deserialization attacks through the RMI protocol. Successful attacks may allow a remote attacker to remotely control the target server and execute Java functions or bytecode.Show less