CWE-306
3,066 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVEs (3,066)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified vectors. |
1Brilliantts 2Fuze Card Ble Firmware Fuze Card Mcu FirmwareJun 17, 2026 Apr 4, 2018 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 An attacker with physical access to a BrilliantTS FUZE card (MCU firmware 0.1.73, BLE firmware 0.7.4) can unlock the card, extract credit card numbers, and tamper with data on the card via Bluetooth because no authentica...Show more |
1Contec Touch 1Smart Home Firmware Jun 17, 2026 Mar 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.php, as demonstrated by changing the admin password and then obtaining control over doors. |
1Trendmicro 1Email Encryption Gateway Jun 17, 2026 Mar 15, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate the registration process of the product to reset configuration parameter...Show more |
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified vectors. |
Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vectors. |
2Fedoraproject Sddm Project2Fedora SddmNov 21, 2024 Mar 8, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication. |
1Siemens 9Digsi 4 En100 Ethernet Module Dnp3 FirmwareEn100 Ethernet Module Iec 104 Firmware+6 moreNov 21, 2024 Mar 8, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 v...Show more |
1Siemens 5En100 Ethernet Module Dnp3 Firmware En100 Ethernet Module Iec 104 FirmwareEn100 Ethernet Module Iec 61850 Firmware+2 moreNov 21, 2024 Mar 8, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module DNP3 variant (All versions < V1.04), EN100 Ethernet module PROFINET IO variant (All versions),...Show more |
1Sap 1Netweaver System Landscape Directory Nov 21, 2024 Mar 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity. |
1Eq 3 1Homematic Central Control Unit Ccu2 Firmware Jun 17, 2026 Feb 22, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eQ-3 AG HomeMatic CCU2 2.29.22 devices have an open XML-RPC port without authentication. This can be exploited by sending arbitrary XML-RPC requests to control the attached BidCos devices. |
This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.3)D5. Authentication is not required to exploit this vulnerability. The...Show more |
1Smiths Medical 1Medfusion 4000 Wireless Syringe Infusion Pump Nov 21, 2024 Feb 15, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An Improper Access Control issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The FTP server on the pump does not require authentication if the pump is config...Show more |
1Cisco 2Rv132w Firmware Rv134w FirmwareNov 21, 2024 Feb 8, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to view configuration parameters for an af...Show more |
1Siemens 5Pxc00/50/100/200 E.d Firmware Pxc00/64/128 U FirmwarePxc001 E.d Firmware+2 moreNov 21, 2024 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability has been identified in Desigo PXC00-E.D V4.10 (All versions < V4.10.111), Desigo PXC00-E.D V5.00 (All versions < V5.0.171), Desigo PXC00-E.D V5.10 (All versions < V5.10.69), Desigo PXC00-E.D V6.00 (All ve...Show more |
SAP Startup Service, SAP KERNEL 7.45, 7.49, and 7.52, is missing an authentication check for functionalities that require user identity and cause consumption of file system storage. |
1Trustwave 1Secure Web Gateway May 13, 2026 Dec 31, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey param...Show more |
Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, triggering a denial of service condition. |
Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device without entering user credentials. The authentication record is stored o...Show more |
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory reset page. An unauthenticated, remote attacker can exploit this vulnerability b...Show more |