CWE-521
259 CVEs • Abstraction: Base
Weak Password Requirements
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
CVEs (259)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Robotic Process Automation For Cloud Pak Jun 17, 2026 Aug 10, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634. |
Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks. |
BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password. |
An empty password in configuration file vulnerability [CWE-258] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.3 and below may...Show more |
1Infiray 1Iray A8z3 Firmware Jun 17, 2026 Jul 17, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in Infiray IRAY-A8Z3 1.0.957. There is a blank root password for TELNET by default. |
1Verizon 2Lvskihp Indoorunit Firmware Lvskihp Outdoorunit FirmwareJun 17, 2026 Jul 14, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static account username/password for access control. This password can be generate...Show more |
1Secheron 1Sepcos Control And Protection Relay Firmware Jun 17, 2026 Jun 24, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Weak default root user credentials allow remote attackers to easily obtain OS superuser privileges over the open TCP port for SSH. |
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The default pre-shared key for the Wi-Fi networks is the same for every router except for the last four digits. The device default pre-shared key for b...Show more |
Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1. |
1Verizon 14g Lte Network Extender Firmware Jun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page. |
Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an account with no password. A remote attacker may potentially exploit this leading t...Show more |
Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2. |
A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cause a Denial of Service (DoS) during password verification. |
The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the other passwords can be changed. The weak password on Linux accounts can be accessed via SSH or Telne...Show more |
Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0. |
IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 210892. |
In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his password could change it to a weak password, such as those with a leng...Show more |
1Globaldatingsoftware 1Premiumdatingscript Jun 17, 2026 Dec 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password reset mechanism in requests\user.php. |
In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of service vulnerability...Show more |
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak. |