VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,961)

page 121 of 149
  • CVE-2025-6920MedJul 1, 2025
    risk 0.34cvss 5.3epss 0.00

    A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* endpoints are expected to enforce API key validation. However, the POST /invocations endpoint failed to do so, resulting in an authentication bypass. This…

  • CVE-2025-1754MedJun 26, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to public projects by sending crafted API requests, potentially…

  • CVE-2025-5876MedJun 9, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability classified as problematic was found in Lucky LM-520-SC, LM-520-FSC and LM-520-FSC-SAM up to 20250321. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authentication. The attack can be launched remotely. The exploit…

  • CVE-2025-5872MedJun 9, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an unknown part of the component Setting Handler. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit…

  • CVE-2025-5871MedJun 9, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in Papendorf SOL Connect Center 3.3.0.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Web Interface. The manipulation leads to missing authentication. The attack may be launched remotely. The…

  • CVE-2025-32738MedMay 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier. If exploited, a remote unauthenticated attacker may change the product settings.

  • CVE-2025-2344MedMar 16, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability, which was classified as critical, has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. Affected by this issue is some unknown functionality of the component API Endpoint. The manipulation leads to missing authentication. The attack may be launched…

  • CVE-2024-52285MedMar 11, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.8), SiPass integrated ACC-AP (All versions < V6.4.8). Affected devices expose several MQTT URLs without authentication. This could allow an unauthenticated remote attacker to access…

  • CVE-2025-23194MedMar 11, 2025
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticated user can set it to an undesired value causing low impact on integrity. There is no impact on confidentiality or availability of…

  • CVE-2025-26360MedFeb 12, 2025
    risk 0.34cvss 5.3epss 0.00

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/persistance/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to delete dashboards via crafted HTTP requests.

  • CVE-2024-47865MedNov 20, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote unauthenticated attacker may update or downgrade the firmware on the device.

  • CVE-2024-39707MedNov 14, 2024
    risk 0.34cvss 5.3epss 0.00

    Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by default, which could lead to a possible roll-back attack in certain platforms. This is fixed in: kernel 5.2, version 05.29.19; kernel 5.3, version 05.38.19;…

  • CVE-2024-26011MedNov 12, 2024
    risk 0.34cvss 5.3epss 0.01

    A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0…

  • CVE-2024-9430MedOct 31, 2024
    risk 0.34cvss 5.3epss 0.00

    The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is vulnerable to unauthorized access of Quote data due to a missing capability check on the ct_tepfw_wp_loaded function in all versions up to, and including, 1.0.0. This makes it possible for…

  • CVE-2024-40091MedOct 21, 2024
    risk 0.34cvss 5.3epss 0.00

    Vilo 5 Mesh WiFi System <= 5.16.1.33 lacks authentication in the Boa webserver, which allows remote, unauthenticated attackers to retrieve logs with sensitive system.

  • CVE-2024-37991MedSep 10, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT…

  • CVE-2024-43272MedAug 19, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authentication for Critical Function vulnerability in icegram Icegram allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Icegram: from n/a through 3.1.24.

  • CVE-2024-36457MedJul 15, 2024
    risk 0.34cvss epss 0.00

    The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint.

  • CVE-2024-21846MedApr 18, 2024
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can reset the board and stop transmitter operations by sending a specially-crafted GET request to the command.cgi gateway, resulting in a denial-of-service scenario.

  • CVE-2024-3774MedApr 15, 2024
    risk 0.34cvss 5.3epss 0.00

    aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.