CWE-306
Missing Authentication for Critical Function
Description
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62
CVEs mapped to this weakness (2,982)
page 79 of 150| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-26363 | Hig | 0.49 | 7.5 | 0.01 | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable an authentication profile server via crafted HTTP requests. | ||
| CVE-2025-26362 | Hig | 0.49 | 7.5 | 0.01 | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to set an arbitrary authentication profile server via crafted HTTP requests. | ||
| CVE-2024-12511 | Hig | 0.49 | 7.6 | 0.01 | Feb 3, 2025 | With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access. | ||
| CVE-2025-0355 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2025 | Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WF1200CRS Ver.1.6.0 and earlier, WG1200CRS Ver.1.5.0 and earlier, GB1200PE Ver.1.3.0 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier,… | ||
| CVE-2024-13186 | Hig | 0.49 | 7.5 | 0.00 | Jan 8, 2025 | The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage. | ||
| CVE-2024-13185 | Hig | 0.49 | 7.5 | 0.00 | Jan 8, 2025 | The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage. | ||
| CVE-2024-13173 | Hig | 0.49 | 7.5 | 0.00 | Jan 8, 2025 | The health module has insufficient restrictions on loading URLs, which may lead to some information leakage. | ||
| CVE-2024-53623 | Hig | 0.49 | 7.5 | 0.00 | Nov 29, 2024 | Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive information. | ||
| CVE-2024-50589 | Hig | 0.49 | 7.5 | 0.01 | Nov 8, 2024 | An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Healthcare Interoperability Resources (FHIR) API to get access to sensitive electronic health records (EHR). | ||
| CVE-2024-48953 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2024 | An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in… | ||
| CVE-2024-48950 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2024 | An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF protections and authentication. | ||
| CVE-2024-5749 | Hig | 0.49 | 7.5 | 0.01 | Oct 15, 2024 | Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials. | ||
| CVE-2024-45276 | Hig | 0.49 | 7.5 | 0.01 | Oct 15, 2024 | An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication. | ||
| CVE-2024-48791 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2024 | An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware update process | ||
| CVE-2024-48777 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2024 | LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process. | ||
| CVE-2024-48776 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2024 | An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process | ||
| CVE-2024-48775 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2024 | An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update process. | ||
| CVE-2024-48774 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2024 | An issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information via the firmware update process. | ||
| CVE-2024-48773 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2024 | An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update process | ||
| CVE-2024-48771 | Hig | 0.49 | 7.5 | 0.00 | Oct 11, 2024 | An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive information via the firmware update process |
- risk 0.49cvss 7.5epss 0.01
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable an authentication profile server via crafted HTTP requests.
- risk 0.49cvss 7.5epss 0.01
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to set an arbitrary authentication profile server via crafted HTTP requests.
- risk 0.49cvss 7.6epss 0.01
With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.
- risk 0.49cvss 7.5epss 0.01
Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WF1200CRS Ver.1.6.0 and earlier, WG1200CRS Ver.1.5.0 and earlier, GB1200PE Ver.1.3.0 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier,…
- risk 0.49cvss 7.5epss 0.00
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
- risk 0.49cvss 7.5epss 0.00
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
- risk 0.49cvss 7.5epss 0.00
The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.
- risk 0.49cvss 7.5epss 0.00
Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive information.
- risk 0.49cvss 7.5epss 0.01
An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Healthcare Interoperability Resources (FHIR) API to get access to sensitive electronic health records (EHR).
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in…
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF protections and authentication.
- risk 0.49cvss 7.5epss 0.01
Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.
- risk 0.49cvss 7.5epss 0.01
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
- risk 0.49cvss 7.5epss 0.00
An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware update process
- risk 0.49cvss 7.5epss 0.00
LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process.
- risk 0.49cvss 7.5epss 0.00
An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process
- risk 0.49cvss 7.5epss 0.00
An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.
- risk 0.49cvss 7.5epss 0.00
An issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information via the firmware update process.
- risk 0.49cvss 7.5epss 0.00
An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update process
- risk 0.49cvss 7.5epss 0.00
An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive information via the firmware update process