VYPR

CWE-303

Incorrect Implementation of Authentication Algorithm

BaseDraft

Description

The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

This incorrect implementation may allow authentication to be bypassed.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-90

CVEs mapped to this weakness (101)

page 2 of 6
  • CVE-2025-13390CriDec 3, 2025
    risk 0.58cvss 10.0epss 0.05

    The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a…

  • CVE-2020-8861HigFeb 22, 2020
    risk 0.58cvss 8.8epss 0.07

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1330 1.10B01 BETA Wi-Fi range extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login…

  • CVE-2026-47300HigJul 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-35579CriMay 5, 2026
    risk 0.57cvss 9.8epss 0.01

    CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. For gRPC and QUIC, the server checks whether the TSIG key name exists in the configuration but never calls…

  • CVE-2026-0073HigMay 4, 2026
    risk 0.57cvss 8.8epss 0.01

    In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed. User interaction…

  • CVE-2025-4676HigJan 7, 2026
    risk 0.57cvss 8.8epss 0.00

    Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.

  • CVE-2025-12421CriNov 27, 2025
    risk 0.57cvss 9.9epss 0.00

    Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a…

  • CVE-2025-12419CriNov 27, 2025
    risk 0.57cvss 9.9epss 0.00

    Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via…

  • CVE-2024-34722HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.00

    In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE pairing due to incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-44420HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link DIR-X3260 prog.cgi Incorrect Implementation of Authentication Algorithm Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-X3260 routers. Authentication is not required…

  • CVE-2023-34282HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link DIR-2150 HNAP Incorrect Implementation of Authentication Algorithm Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-2150 routers. Authentication is not required to…

  • CVE-2023-34274HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link DIR-2150 LoginPassword Incorrect Implementation of Authentication Algorithm Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-2150 routers. Authentication is not…

  • CVE-2023-31211HigJan 12, 2024
    risk 0.57cvss 8.8epss 0.01

    Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials

  • CVE-2022-39366CriOct 28, 2022
    risk 0.57cvss 9.9epss 0.01

    DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not verify the signature of JWT tokens. This allows an attacker to connect to DataHub instances as any user if Metadata Service…

  • CVE-2020-15632HigJul 23, 2020
    risk 0.57cvss 8.8epss 0.03

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-842 3.13B05 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of HNAP GetCAPTCHAsetting…

  • CVE-2025-53782HigOct 14, 2025
    risk 0.55cvss 8.4epss 0.00

    Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-28446CriMar 5, 2026
    risk 0.54cvss 9.4epss 0.01

    OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound allowlist policy validation that accepts empty caller IDs and uses suffix-based matching instead of strict equality. Remote attackers…

  • CVE-2025-14510HigJan 16, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Ability OPTIMAX: 6.1, 6.2, from 6.3.0 before 6.3.1-251120, from 6.4.0 before 6.4.1-251120.

  • CVE-2025-44557HigJun 27, 2025
    risk 0.53cvss 8.1epss 0.00

    A state machine transition flaw in the Bluetooth Low Energy (BLE) stack of Cypress PSoC4 v3.66 allows attackers to bypass the pairing process and authentication via a crafted pairing_failed packet.

  • CVE-2021-21902HigDec 22, 2021
    risk 0.53cvss 8.1epss 0.02

    An authentication bypass vulnerability exists in the CMA run_server_6877 functionality of Garrett Metal Detectors iC Module CMA Version 5.0. A properly-timed network connection can lead to authentication bypass via session hijacking. An attacker can send a sequence of requests…