VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (2,982)

page 79 of 150
  • CVE-2025-26363HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable an authentication profile server via crafted HTTP requests.

  • CVE-2025-26362HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to set an arbitrary authentication profile server via crafted HTTP requests.

  • CVE-2024-12511HigFeb 3, 2025
    risk 0.49cvss 7.6epss 0.01

    With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.

  • CVE-2025-0355HigJan 15, 2025
    risk 0.49cvss 7.5epss 0.01

    Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WF1200CRS Ver.1.6.0 and earlier, WG1200CRS Ver.1.5.0 and earlier, GB1200PE Ver.1.3.0 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier,…

  • CVE-2024-13186HigJan 8, 2025
    risk 0.49cvss 7.5epss 0.00

    The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.

  • CVE-2024-13185HigJan 8, 2025
    risk 0.49cvss 7.5epss 0.00

    The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.

  • CVE-2024-13173HigJan 8, 2025
    risk 0.49cvss 7.5epss 0.00

    The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.

  • CVE-2024-53623HigNov 29, 2024
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive information.

  • CVE-2024-50589HigNov 8, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Healthcare Interoperability Resources (FHIR) API to get access to sensitive electronic health records (EHR).

  • CVE-2024-48953HigNov 7, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in…

  • CVE-2024-48950HigNov 7, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF protections and authentication.

  • CVE-2024-5749HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.

  • CVE-2024-45276HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.

  • CVE-2024-48791HigOct 14, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware update process

  • CVE-2024-48777HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48776HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process

  • CVE-2024-48775HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48774HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information via the firmware update process.

  • CVE-2024-48773HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update process

  • CVE-2024-48771HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive information via the firmware update process