VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 76 of 150
  • CVE-2021-47802HigJan 21, 2026
    risk 0.49cvss 7.5epss 0.01

    Tenda D151 and D301 routers contain an unauthenticated configuration download vulnerability that allows remote attackers to retrieve router configuration files. Attackers can send a request to /goform/getimage endpoint to download configuration data including admin credentials…

  • CVE-2026-1023HigJan 16, 2026
    risk 0.49cvss 7.5epss 0.00

    Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly exploit a specific functionality to query database contents.

  • CVE-2025-66049HigJan 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network access to view the…

  • CVE-2017-20213HigJan 8, 2026
    risk 0.49cvss 7.5epss 0.00

    FLIR Thermal Camera F/FC/PT/D Stream firmware version 8.0.0.64 contains an unauthenticated vulnerability that allows remote attackers to access live camera streams without credentials. Attackers can exploit the vulnerability to view unauthorized thermal camera video feeds across…

  • CVE-2020-36904HigDec 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrary Windows binaries by manipulating the NO_LIST_EXE_PATH configuration parameter. Attackers can bypass authentication through the /cps/ endpoint and modify…

  • CVE-2022-50790HigDec 30, 2025
    risk 0.49cvss 7.5epss 0.01

    SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit the vulnerability by calling specific web scripts to…

  • CVE-2025-66377HigDec 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operation of other nodes within the installation.

  • CVE-2025-3232HigDec 24, 2025
    risk 0.49cvss 7.5epss 0.01

    A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arbitrary OS commands.

  • CVE-2019-25248HigDec 24, 2025
    risk 0.49cvss 7.5epss 0.00

    Beward N100 M2.1.6.04C014 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve the camera's RTSP stream by exploiting the lack of authentication in the video access mechanism.

  • CVE-2018-25141HigDec 24, 2025
    risk 0.49cvss 7.5epss 0.00

    FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve video streams by accessing specific endpoints like /live.mjpeg, /snapshot.jpg, and RTSP streaming…

  • CVE-2018-25140HigDec 24, 2025
    risk 0.49cvss 7.5epss 0.00

    FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information,…

  • CVE-2018-25139HigDec 24, 2025
    risk 0.49cvss 7.5epss 0.00

    FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly connect to the RTSP stream using tools like VLC or FFmpeg to view and record thermal camera footage.

  • CVE-2018-25137HigDec 24, 2025
    risk 0.49cvss 7.5epss 0.00

    FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows attackers to download sensitive configuration files. Attackers can exploit the getConfigExportFile.cgi endpoint to retrieve system configurations, potentially…

  • CVE-2018-25136HigDec 24, 2025
    risk 0.49cvss 7.5epss 0.00

    FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can retrieve video stream images by directly accessing multiple image endpoints like middleImage.jpg,…

  • CVE-2023-53974HigDec 22, 2025
    risk 0.49cvss 7.5epss 0.01

    D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings through a POST request. Attackers can send a specific POST request to the router's configuration endpoint to download a complete backup…

  • CVE-2023-53970HigDec 22, 2025
    risk 0.49cvss 7.5epss 0.01

    Screen SFT DAB 600/C Firmware 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP-bound session identifiers. Attackers can exploit the vulnerable deviceManagement API endpoint to reset device configurations…

  • CVE-2023-53969HigDec 22, 2025
    risk 0.49cvss 7.5epss 0.01

    Screen SFT DAB 600/C firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to…

  • CVE-2023-53967HigDec 22, 2025
    risk 0.49cvss 7.5epss 0.01

    Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without requiring the current credentials. Attackers can exploit the userManager.cgx API endpoint by sending a crafted POST request with a new…

  • CVE-2023-53896HigDec 16, 2025
    risk 0.49cvss 7.5epss 0.01

    D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configuration settings without authentication. Attackers can exploit the /cgi-bin/ExportSettings.sh endpoint to retrieve sensitive…

  • CVE-2020-36894HigDec 10, 2025
    risk 0.49cvss 7.5epss 0.01

    Eibiz i-Media Server Digital Signage 3.8.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through AMF-encoded object manipulation. Attackers can send crafted serialized objects to the /messagebroker/amf endpoint to…