VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 43 of 150
  • CVE-2024-45438CriAug 21, 2025
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a…

  • CVE-2025-43983CriAug 14, 2025
    risk 0.59cvss 9.1epss 0.00

    KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/goform_set_cmd_process and goform/goform_get_cmd_process. These allow an unauthenticated attacker to retrieve sensitive information (including the device admin…

  • CVE-2025-3461CriJun 8, 2025
    risk 0.59cvss 9.1epss 0.01

    The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Missing Authentication for Critical Function," and is estimated as a CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi…

  • CVE-2024-55585CriJun 7, 2025
    risk 0.59cvss epss 0.00

    In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read and write access, as demonstrated by /api/v1/users/resetpassword.

  • CVE-2025-40664CriMay 26, 2025
    risk 0.59cvss 9.1epss 0.01

    Missing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /frmGestionUser.aspx/GetData, /frmGestionUser.aspx/updateUser and /frmGestionUser.aspx/DeleteUser.

  • CVE-2025-4557CriMay 12, 2025
    risk 0.59cvss 9.1epss 0.01

    The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific APIs and operate system functions. These functions include opening gates and restarting the system.

  • CVE-2024-23943CriMar 18, 2025
    risk 0.59cvss 9.1epss 0.01

    An unauthenticated remote attacker can gain access to the cloud API due to a lack of authentication for a critical function in the affected devices. Availability is not affected.

  • CVE-2025-0159CriFeb 28, 2025
    risk 0.59cvss 9.1epss 0.01

    IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1) could allow a…

  • CVE-2025-26361CriFeb 12, 2025
    risk 0.59cvss 9.1epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to factory reset the device via crafted HTTP requests.

  • CVE-2025-21198CriFeb 11, 2025
    risk 0.59cvss 9.0epss 0.01

    Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability

  • CVE-2024-39273CriJan 14, 2025
    risk 0.59cvss 9.0epss 0.01

    A firmware update vulnerability exists in the fw_check.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary firmware update. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

  • CVE-2024-47406CriOct 25, 2024
    risk 0.59cvss 9.1epss 0.01

    Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability.

  • CVE-2024-26519CriOct 22, 2024
    risk 0.59cvss 9.0epss 0.00

    An issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the /www/cgi-bin/nas.cgi component.

  • CVE-2024-35293CriOct 2, 2024
    risk 0.59cvss 9.1epss 0.01

    An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resulting in data loss and/or a DoS.

  • CVE-2024-6592CriSep 25, 2024
    risk 0.59cvss 9.1epss 0.01

    An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications…

  • CVE-2024-41259CriAug 1, 2024
    risk 0.59cvss 9.1epss 0.00

    Use of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's account information.

  • CVE-2024-32752CriJun 6, 2024
    risk 0.59cvss 9.1epss 0.01

    The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attacker to gain unauthorized access

  • CVE-2020-26942CriMar 21, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminPassword operation request, subsequently setting a new arbitrary password for the admin account.

  • CVE-2023-51947CriJan 19, 2024
    risk 0.59cvss 9.1epss 0.01

    Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types of data without authentication.

  • CVE-2023-43271CriOct 9, 2023
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the driving recorder through ftp and other protocols.