VYPR

CWE-306

Missing Authentication for Critical Function

BaseDraftLikelihood: High

Description

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-12 · CAPEC-166 · CAPEC-216 · CAPEC-36 · CAPEC-62

CVEs mapped to this weakness (3,362)

page 92 of 169
  • CVE-2025-6678HigJun 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations.…

  • CVE-2025-32978HigJun 24, 2025
    risk 0.49cvss 7.5epss 0.01

    Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unauthenticated users to replace system licenses through a web interface intended…

  • CVE-2025-26468HigJun 9, 2025
    risk 0.49cvss 7.5epss 0.00

    CyberData  011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a denial-of-service condition or system disruption.

  • CVE-2025-5192HigJun 6, 2025
    risk 0.49cvss 7.5epss 0.01

    A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to bypass authentication and access application functions.

  • CVE-2025-41655HigMay 26, 2025
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated remote attacker can access a URL which causes the device to reboot.

  • CVE-2024-23815HigMay 13, 2025
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is allowed from networks outside of a highly protected zone), Desigo CC (All versions if access from Installed Clients to Desigo CC server is only allowed within…

  • CVE-2025-29870HigApr 9, 2025
    risk 0.49cvss 7.5epss 0.01

    Missing authentication for critical function vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote unauthenticated attacker may obtain the product configuration information including authentication information.

  • CVE-2025-25068HigMar 21, 2025
    risk 0.49cvss 7.5epss 0.00

    Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers to bypass MFA protections via API requests to plugin-specific routes.

  • CVE-2025-30111HigMar 18, 2025
    risk 0.49cvss 7.5epss 0.00

    On IROAD v9 devices, one can Remotely Dump Video Footage and the Live Video Stream. The dashcam exposes endpoints that allow unauthorized users, who gained access through other means, to list and download recorded videos, as well as access live video streams without proper…

  • CVE-2025-25500HigMar 18, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a lack of runtime capability validation. This allows attackers to deploy a contract without capability enforcement, and execute unauthorized actions on the…

  • CVE-2025-25224HigFeb 18, 2025
    risk 0.49cvss 7.5epss 0.01

    The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained.

  • CVE-2025-26366HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to disable front panel authentication via crafted HTTP requests.

  • CVE-2025-26365HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable front panel authentication via crafted HTTP requests.

  • CVE-2025-26364HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to disable an authentication profile server via crafted HTTP requests.

  • CVE-2025-26363HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable an authentication profile server via crafted HTTP requests.

  • CVE-2025-26362HigFeb 12, 2025
    risk 0.49cvss 7.5epss 0.01

    A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to set an arbitrary authentication profile server via crafted HTTP requests.

  • CVE-2024-12511HigFeb 3, 2025
    risk 0.49cvss 7.6epss 0.01

    With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.

  • CVE-2025-0355HigJan 15, 2025
    risk 0.49cvss 7.5epss 0.01

    Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WF1200CRS Ver.1.6.0 and earlier, WG1200CRS Ver.1.5.0 and earlier, GB1200PE Ver.1.3.0 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier,…

  • CVE-2024-13186HigJan 8, 2025
    risk 0.49cvss 7.5epss 0.00

    The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.

  • CVE-2024-13185HigJan 8, 2025
    risk 0.49cvss 7.5epss 0.00

    The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.