VYPR

CWE-305

Authentication Bypass by Primary Weakness

BaseDraft

Description

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (159)

page 1 of 8
  • CVE-2025-31161CriKEVApr 3, 2025
    risk 0.93cvss 9.8epss 1.00

    CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as exploited in the wild in March and April 2025, aka "Unauthenticated HTTP(S) port access." A race condition exists in the…

  • CVE-2023-34124CriJul 13, 2023
    risk 0.70cvss 9.8epss 0.46

    The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • CVE-2020-10923HigJul 28, 2020
    risk 0.67cvss 8.8epss 0.85

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UPnP service, which listens on…

  • CVE-2025-4320CriJan 23, 2026
    risk 0.65cvss 10.0epss 0.00

    Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery Exploitation. This issue affects Sufirmam: through…

  • CVE-2025-32011CriMay 1, 2025
    risk 0.65cvss 9.8epss 0.27

    KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get access due to a path traversal.

  • CVE-2025-24522CriMay 1, 2025
    risk 0.65cvss 10.0epss 0.01

    KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying…

  • CVE-2021-26102CriDec 19, 2024
    risk 0.65cvss 9.8epss 0.17

    A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. In particular, deleting specific configuration files will reset…

  • CVE-2024-36388CriJun 2, 2024
    risk 0.65cvss 10.0epss 0.00

    MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function

  • CVE-2024-1403CriFeb 27, 2024
    risk 0.65cvss 10.0epss 0.03

    In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified.  The vulnerability is a bypass to authentication based on a failure to properly…

  • CVE-2026-25555CriJun 8, 2026
    risk 0.64cvss 9.8epss 0.02

    OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value. Attackers can exploit the middleware's comparison…

  • CVE-2026-4670CriApr 30, 2026
    risk 0.64cvss 9.8epss 0.06

    Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

  • CVE-2025-13915CriDec 26, 2025
    risk 0.64cvss 9.8epss 0.09

    IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.

  • CVE-2025-41733CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.01

    The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.

  • CVE-2025-36386CriOct 28, 2025
    risk 0.64cvss 9.8epss 0.01

    IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.

  • CVE-2025-53826CriJul 15, 2025
    risk 0.64cvss 9.8epss 0.01

    File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs…

  • CVE-2025-46801CriMay 19, 2025
    risk 0.64cvss 9.8epss 0.01

    Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerability is exploited, an attacker may be able to log in to the system as an arbitrary user, allowing them to read or tamper with data in the…

  • CVE-2025-4658CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.00

    Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on the OpenPubkey library for authentication, this vulnerability in OpenPubkey also applies to OPKSSH versions…

  • CVE-2025-3757CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.00

    Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.

  • CVE-2024-50478CriOct 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: 1.4.5.

  • CVE-2023-41920CriJul 2, 2024
    risk 0.64cvss 9.8epss 0.00

    The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the device is configured with the IP address of 10.10.10.10, the root user is automatically logged in.