VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (950)

page 5 of 48
  • CVE-2018-5402CriOct 8, 2018
    risk 0.59cvss 9.1epss 0.01

    The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App use an embedded webserver that uses unencrypted plaintext for the transmission of the administrator PIN Impact: An attacker once authenticated can change configurations, upload new configuration files, and…

  • CVE-2018-5401CriOct 8, 2018
    risk 0.59cvss 9.1epss 0.01

    The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App transmit sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. The devices transmit process control information via unencrypted Modbus…

  • CVE-2018-6018CriJan 24, 2018
    risk 0.59cvss 9.1epss 0.01

    Fixed sizes of HTTPS responses in Tinder iOS app and Tinder Android app allow an attacker to extract private sensitive information by sniffing network traffic.

  • CVE-2018-6017CriJan 24, 2018
    risk 0.59cvss 9.1epss 0.01

    Unencrypted transmission of images in Tinder iOS app and Tinder Android app allows an attacker to extract private sensitive information by sniffing network traffic.

  • CVE-2023-25437HigApr 27, 2023
    risk 0.58cvss 8.8epss 0.14

    An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges and gain sensitive information due to cleartext passwords passed in the raw HTML.

  • CVE-2026-73174HigSep 16, 2026
    risk 0.57cvss —epss 0.00

    Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive observer to intercept management traffic…

  • CVE-2026-45432HigJun 4, 2026
    risk 0.57cvss —epss 0.00

    This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management interface. A remote attacker could exploit this vulnerability by intercepting network traffic to obtain sensitive authentication information,…

  • CVE-2026-42514HigApr 29, 2026
    risk 0.57cvss —epss 0.00

    This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker could exploit this vulnerability by intercepting API responses containing valid OTPs. Successful exploitation of this vulnerability could allow an attacker to…

  • CVE-2026-22080HigJan 9, 2026
    risk 0.57cvss —epss 0.00

    This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the transmission of credentials encoded using reversible Base64 encoding through the web-based administrative interface. An attacker on the same network could…

  • CVE-2026-22079HigJan 9, 2026
    risk 0.57cvss —epss 0.00

    This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of login credentials during the initial login or post-factory reset setup through the web-based administrative interface. An attacker on…

  • CVE-2026-22544HigJan 7, 2026
    risk 0.57cvss —epss 0.00

    An attacker with a network connection could detect credentials in clear text.

  • CVE-2023-53875HigDec 15, 2025
    risk 0.57cvss 8.8epss 0.00

    GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attackers can redirect victims using a malicious URL shortcut and WebDAV technique to run a reverse…

  • CVE-2025-50110HigSep 15, 2025
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sensitive information - including internal server URLs, account IDs, passwords, and device tokens - as plaintext query…

  • CVE-2025-52351HigAug 21, 2025
    risk 0.57cvss 8.8epss 0.00

    Aikaan IoT management platform v3.25.0325-5-g2e9c59796 sends a newly generated password to users in plaintext via email and also includes the same password as a query parameter in the account activation URL (e.g., https://domain.com/activate=xyz). This practice can result in…

  • CVE-2025-53756HigJul 16, 2025
    risk 0.57cvss —epss 0.00

    This vulnerability exists in Digisol DG-GR6821AC Router due to cleartext transmission of credentials in its web management interface. A remote attacker could exploit this vulnerability by intercepting the network traffic and capturing cleartext credentials. Successful…

  • CVE-2025-42603HigApr 23, 2025
    risk 0.57cvss —epss 0.00

    This vulnerability exists in the Meon KYC solutions due to transmission of sensitive data in plain text within the response payloads of certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting API response that contains unencrypted…

  • CVE-2025-0556HigFeb 12, 2025
    risk 0.57cvss 8.8epss 0.00

    In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non-sensitive information between the service agent process and app host process occurs over an unencrypted tunnel, which can be…

  • CVE-2025-0631HigJan 28, 2025
    risk 0.57cvss —epss 0.00

    A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using HTTP resulting in credentials being sent in clear text.

  • CVE-2024-50634HigNov 8, 2024
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in a weak JWT token in Watcharr v1.43.0 and below allows attackers to perform privilege escalation using a crafted JWT token. This vulnerability is not limited to privilege escalation but also affects all functions that require authentication.

  • CVE-2024-47789HigOct 4, 2024
    risk 0.57cvss —epss 0.00

    ** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of weak authentication scheme of the HTTP header protocol where authorization tag contain a Base-64 encoded username and password. A remote attacker could exploit this…