CWE-306
3,068 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (3,068)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Medtronic 20Amplia Crt D Firmware Carelink 2090 FirmwareCarelink Monitor Firmware+17 moreJun 17, 2026 Mar 25, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Co...Show more |
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/LoadDefaultSettings to reset the router witho...Show more |
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/form2userconfig.cgi to edit the system accoun...Show more |
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use a hidden API URL /goform/SystemCommand to execute a system comma...Show more |
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/setSysAdm to edit the web or system account w...Show more |
1Teracue 3Enc 400 Hdmi2 Firmware Enc 400 Hdmi FirmwareEnc 400 Hdsdi FirmwareNov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be interacted with, a large portion of the HTTP endpoints are missing authent...Show more |
1Nokia 1I 240w Q Gpon Ont Firmware Jun 17, 2026 Mar 5, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 allows a remote, unauthenticated attacker to enable telnetd on the router via a crafted HTTP request. |
Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath binary. If an attacker provides one at an arbitrary location it is executed with root privileges |
The Glen Dimplex Deutschland GmbH implementation of the Carel pCOWeb configuration tool allows remote attackers to obtain access via an HTTP session on port 10000, as demonstrated by reading the modem password (which is...Show more |
1Phoenixcontact 8Axc 1050 Firmware Ilc 131 Eth/xc FirmwareIlc 131 Eth Firmware+5 moreJun 17, 2026 Feb 26, 2019 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all director...Show more |
An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does not require authentication via the HNAP_AUTH HTTP header. |
3Opensourcebms ThinkphpZzzcms3Open Source Background Management System ThinkphpZzzphpJun 17, 2026 Feb 24, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed...Show more |
1Netis Systems 2Wf2411 Firmware Wf2880 FirmwareJun 17, 2026 Feb 21, 2019 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (devi...Show more |
Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users. Fixed in 1.0.97 to 1.0.99 (ru...Show more |
1Aveva 2Indusoft Web Studio Intouch Machine Edition 2014Jun 17, 2026 Feb 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could le...Show more |
1Kunbus 1Pr100088 Modbus Gateway Firmware Jun 17, 2026 Feb 12, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166). |
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to hijack the DNS service configuration of all clients in the WLAN, wi...Show more |
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with the firmware 1.02B03. There is incorrect access control allowing remote attackers to reset the router without authentication via the SetFactoryDefau...Show more |
1Estrongs 1Es File Explorer File Manager Jun 17, 2026 Jan 16, 2019 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port re...Show more |
1Cisco 1Policy Suite For Mobile Nov 21, 2024 Jan 11, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface. The attacke...Show more |