← Back
CWE-521

259 CVEs • Abstraction: Base

Weak Password Requirements

The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.

JSON object

Loading...

CVEs (259)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Robotic Process Automation For Cloud Pak
Jun 17, 2026
Aug 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634.
1Raneto Project
1Raneto
Jun 17, 2026
Aug 4, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks.
1Bosch
1Bf Os
Jun 17, 2026
Aug 1, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password.
1Fortinet
1Fortinac
Jun 17, 2026
Jul 18, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An empty password in configuration file vulnerability [CWE-258] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.3 and below may...Show more
An empty password in configuration file vulnerability [CWE-258] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.3 and below may allow an authenticated attacker to access the MySQL databases via the CLI.Show less
1Infiray
1Iray A8z3 Firmware
Jun 17, 2026
Jul 17, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in Infiray IRAY-A8Z3 1.0.957. There is a blank root password for TELNET by default.
1Verizon
2Lvskihp Indoorunit Firmware
Lvskihp Outdoorunit Firmware
Jun 17, 2026
Jul 14, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static account username/password for access control. This password can be generate...Show more
On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static account username/password for access control. This password can be generated via a binary included in the firmware, after ascertaining the MAC address of the IDU's base Ethernet interface, and adding the string DEVICE_MANUFACTURER='Wistron_NeWeb_Corp.' to /etc/device_info to replicate the host environment. This occurs in /etc/init.d/wnc_factoryssidkeypwd (IDU).Show less
1Secheron
1Sepcos Control And Protection Relay Firmware
Jun 17, 2026
Jun 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Weak default root user credentials allow remote attackers to easily obtain OS superuser privileges over the open TCP port for SSH.
1Trendnet
1Tew 831dr Firmware
Jun 17, 2026
Jun 16, 2022
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The default pre-shared key for the Wi-Fi networks is the same for every router except for the last four digits. The device default pre-shared key for b...Show more
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The default pre-shared key for the Wi-Fi networks is the same for every router except for the last four digits. The device default pre-shared key for both 2.4 GHz and 5 GHz networks can be guessed or brute-forced by an attacker within range of the Wi-Fi network.Show less
1Kromit
1Titra
Jun 17, 2026
Jun 16, 2022
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.
1Verizon
14g Lte Network Extender Firmware
Jun 17, 2026
Jun 2, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.
1Dell
1Powerscale Onefs
Jun 17, 2026
Jun 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an account with no password. A remote attacker may potentially exploit this leading t...Show more
Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an account with no password. A remote attacker may potentially exploit this leading to a user account compromise.Show less
1Trudesk Project
1Trudesk
Jun 17, 2026
May 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2.
1Zammad
1Zammad
Jun 17, 2026
Apr 27, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cause a Denial of Service (DoS) during password verification.
1Redlion
1Da50n Firmware
Jun 17, 2026
Apr 20, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the other passwords can be changed. The weak password on Linux accounts can be accessed via SSH or Telne...Show more
The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the other passwords can be changed. The weak password on Linux accounts can be accessed via SSH or Telnet, the former of which is by default enabled on trusted interfaces. While the SSH service does not support root login, a user logging in using either of the other Linux accounts may elevate to root access using the su command if they have access to the associated password.Show less
1Weseek
1Growi
Jun 17, 2026
Apr 5, 2022
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.
1Ibm
1Maximo Asset Management
Jun 17, 2026
Feb 18, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 210892.
1Daybydaycrm
1Daybyday Crm
Jun 17, 2026
Jan 5, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his password could change it to a weak password, such as those with a leng...Show more
In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his password could change it to a weak password, such as those with a length of a single character. This may allow an attacker to brute-force users’ passwords with minimal to no computational effort.Show less
1Globaldatingsoftware
1Premiumdatingscript
Jun 17, 2026
Dec 9, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password reset mechanism in requests\user.php.
1Canon
1Lbp223dw Firmware
Jun 17, 2026
Dec 6, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of service vulnerability...Show more
In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of service vulnerability.Show less
1Kaseya
1Unitrends Backup
Jun 17, 2026
Dec 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.