VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,361)

page 89 of 169
  • CVE-2026-2754HigMar 6, 2026
    risk 0.49cvss 7.5epss 0.01

    Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. An unauthenticated remote attacker with network access to the device can execute HTTP GET requests to TCP port 8080 to retrieve internal network parameters…

  • CVE-2026-27603HigMar 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4, the chart filter endpoint POST /project/:project_id/chart/:chart_id/filter is missing both verifyToken and checkPermissions…

  • CVE-2026-2844HigFeb 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects TimePictra: from 11.0 through 11.3 SP2.

  • CVE-2026-27449HigFeb 26, 2026
    risk 0.49cvss 7.5epss 0.01

    Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where certain API endpoints are exposed without enforcing authentication or authorization checks. The affected endpoints can be accessed…

  • CVE-2026-26340HigFeb 24, 2026
    risk 0.49cvss 7.5epss 0.01

    Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote attacker can connect to the RTSP service and access live video/audio streams without valid credentials, resulting in unauthorized…

  • CVE-2026-26048HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    The Wi-Fi router is vulnerable to de-authentication attacks due to the absence of management frame protection, allowing forged deauthentication and disassociation frames to be broadcast without authentication or encryption. An attacker can use this to cause unauthorized…

  • CVE-2025-70147HigFeb 18, 2026
    risk 0.49cvss 7.5epss 0.01

    Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET requests to these endpoints without a…

  • CVE-2026-26055HigFeb 12, 2026
    risk 0.49cvss 7.5epss 0.01

    Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of Yoke. The ATC webhook endpoints lack proper authentication mechanisms, allowing any pod within the cluster…

  • CVE-2020-37157HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and…

  • CVE-2020-37146HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration files. Attackers can access the camera's configuration backup by sending a GET request to the /config_backup.bin endpoint,…

  • CVE-2022-50978HigFeb 2, 2026
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).

  • CVE-2022-50977HigFeb 2, 2026
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via HTTP.

  • CVE-2026-25116HigJan 29, 2026
    risk 0.49cvss 7.6epss 0.01

    Runtipi is a personal homeserver orchestrator. Starting in version 4.5.0 and prior to version 4.7.2, an unauthenticated Path Traversal vulnerability in the `UserConfigController` allows any remote user to overwrite the system's `docker-compose.yml` configuration file. By…

  • CVE-2020-36963HigJan 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to download router configuration files. Attackers can send a specific HTTP GET request to /cgi-bin/DownloadCfg/RouterCfm.cfg to retrieve…

  • CVE-2021-47802HigJan 21, 2026
    risk 0.49cvss 7.5epss 0.01

    Tenda D151 and D301 routers contain an unauthenticated configuration download vulnerability that allows remote attackers to retrieve router configuration files. Attackers can send a request to /goform/getimage endpoint to download configuration data including admin credentials…

  • CVE-2026-1023HigJan 16, 2026
    risk 0.49cvss 7.5epss 0.01

    Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly exploit a specific functionality to query database contents.

  • CVE-2025-66049HigJan 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network access to view the…

  • CVE-2017-20213HigJan 8, 2026
    risk 0.49cvss 7.5epss 0.00

    FLIR Thermal Camera F/FC/PT/D Stream firmware version 8.0.0.64 contains an unauthenticated vulnerability that allows remote attackers to access live camera streams without credentials. Attackers can exploit the vulnerability to view unauthorized thermal camera video feeds across…

  • CVE-2020-36904HigDec 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrary Windows binaries by manipulating the NO_LIST_EXE_PATH configuration parameter. Attackers can bypass authentication through the /cps/ endpoint and modify…

  • CVE-2022-50790HigDec 30, 2025
    risk 0.49cvss 7.5epss 0.01

    SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit the vulnerability by calling specific web scripts to…