VYPR

CWE-521

Weak Password Requirements

BaseDraft

Description

The product does not require that users should have strong passwords.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-16 · CAPEC-49 · CAPEC-509 · CAPEC-55 · CAPEC-555 · CAPEC-561 · CAPEC-565 · CAPEC-70

CVEs mapped to this weakness (264)

page 1 of 14
  • CVE-2026-25715CriFeb 20, 2026
    risk 0.64cvss 9.8epss 0.01

    The web management interface of the device allows the administrator username and password to be set to blank values. Once applied, the device permits authentication with empty credentials over the web management interface and Telnet service. This effectively disables …

  • CVE-2025-53963CriDec 4, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The root account has a weak default password of ionadmin, and a password change policy for the root account is not enforced. Thus, an…

  • CVE-2025-63747CriNov 17, 2025
    risk 0.64cvss 9.8epss 0.00

    QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the account provides administrative privileges in the default configuration, an attacker who can reach the…

  • CVE-2025-12552CriOct 31, 2025
    risk 0.64cvss 9.8epss 0.00

    Insufficient Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

  • CVE-2025-12364CriOct 27, 2025
    risk 0.64cvss 9.8epss 0.00

    Weak Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

  • CVE-2025-12285CriOct 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Missing Initial Password Change.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

  • CVE-2025-30127CriAug 6, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings (containing sensitive routes, conversations, and footage) are open for downloading by creating a socket to command port…

  • CVE-2025-28389CriJun 13, 2025
    risk 0.64cvss 9.8epss 0.01

    Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.

  • CVE-2025-28200CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.

  • CVE-2025-25211CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker unauthorized access and login.

  • CVE-2025-27663CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.00

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Weak Password Encryption / Encoding OVE-20230524-0007.

  • CVE-2024-48845CriDec 5, 2024
    risk 0.64cvss 9.4epss 0.02

    Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access.  Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02

  • CVE-2024-42850CriAug 16, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.

  • CVE-2024-3263CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of improper method for system credentials generation and weak password policy, passwords can be easily guessed and enumerated through brute force attacks.…

  • CVE-2023-49238CriJan 9, 2024
    risk 0.64cvss 9.8epss 0.01

    In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Although this password must be changed upon the first login, it is possible that an…

  • CVE-2023-24049CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credential management.

  • CVE-2023-29974CriNov 8, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.

  • CVE-2023-37756CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easily guess users' passwords via a bruteforce attack.

  • CVE-2022-32513CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker brute forces the password. Affected Products: C-Bus Network Automation Controller - LSS5500NAC (Versions prior to V1.10.0), Wiser for C-Bus…

  • CVE-2022-44236CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) has a Weak password vulnerability.