CWE-521
Weak Password Requirements
Description
The product does not require that users should have strong passwords.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-112 · CAPEC-16 · CAPEC-49 · CAPEC-509 · CAPEC-55 · CAPEC-555 · CAPEC-561 · CAPEC-565 · CAPEC-70
CVEs mapped to this weakness (264)
page 13 of 14| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-10320 | Low | 0.20 | 3.1 | 0.00 | Sep 12, 2025 | A vulnerability was detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue affects some unknown processing of the file /admin/user/updatePwd. Performing manipulation results in weak password requirements. Remote exploitation of the attack is possible. A high degree of… | ||
| CVE-2023-27272 | Low | 0.20 | 3.1 | 0.00 | Apr 14, 2025 | IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system. | ||
| CVE-2024-0188 | Low | 0.20 | 3.1 | 0.01 | Jan 2, 2024 | A vulnerability, which was classified as problematic, was found in RRJ Nueva Ecija Engineer Online Portal 1.0. This affects an unknown part of the file change_password_teacher.php. The manipulation leads to weak password requirements. It is possible to initiate the attack… | ||
| CVE-2023-7053 | Low | 0.20 | 3.1 | 0.01 | Dec 22, 2023 | A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user/signup.php. The manipulation leads to weak password requirements. The attack can be initiated remotely. The… | ||
| CVE-2025-65014 | Low | 0.17 | 3.7 | 0.00 | Nov 18, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password policy vulnerability was identified in the user management functionality of the LibreNMS application. This vulnerability allows administrators to create… | ||
| CVE-2024-29208 | Low | 0.14 | 2.2 | 0.00 | May 7, 2024 | An Unverified Password Change could allow a malicious actor with API access to the device to change the system password without knowing the previous password. Affected Products: UniFi Connect EV Station (Version 1.1.18 and earlier) UniFi Connect EV Station Pro (Version… | ||
| CVE-2026-1408 | Low | 0.13 | 2.0 | 0.00 | Jan 25, 2026 | A weakness has been identified in Beetel 777VR1 up to 01.00.09/01.00.09_55. This vulnerability affects unknown code of the component UART Interface. Executing a manipulation can lead to weak password requirements. The physical device can be targeted for the attack. The attack… | ||
| CVE-2026-34203 | Low | 0.11 | 2.7 | 0.00 | Mar 31, 2026 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creation and editing via the REST API fails to apply the password validation rules defined by Django's AUTH_PASSWORD_VALIDATORS setting (which defaults to an empty… | ||
| CVE-2012-2441 | 0.04 | — | 0.09 | Apr 28, 2012 | RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) SSH… | |||
| CVE-2026-12504 | Hig | 0.00 | — | 0.00 | Jul 24, 2026 | Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a password and obtain a root shell via an… | ||
| CVE-2026-56577 | Low | 0.00 | 3.1 | 0.00 | Jul 21, 2026 | HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks. | ||
| CVE-2026-35097 | Med | 0.00 | — | 0.00 | Jun 30, 2026 | KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any alphabetic, special, or extended characters. This issue was fixed in the patch published in June 2026. | ||
| CVE-2025-48372 | Hig | 0.00 | 7.3 | 0.00 | May 22, 2025 | Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time Password (OTP). Prior to version 1.0.1, even if a secure random number generator is used, the short length and limited range (1000–9999) results in only… | ||
| CVE-2024-47221 | Hig | 0.00 | 7.5 | 0.00 | Sep 22, 2024 | CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password. | ||
| CVE-2023-3423 | Hig | 0.00 | 8.8 | 0.01 | Jun 27, 2023 | Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0. | ||
| CVE-2023-22451 | Med | 0.00 | 6.5 | 0.01 | Jan 2, 2023 | Kiwi TCMS is an open source test management system. In version 11.6 and prior, when users register new accounts and/or change passwords, there is no validation in place which would prevent them from picking an easy to guess password. This issue is resolved by providing defaults… | ||
| CVE-2022-41969 | Low | 0.00 | 2.4 | 0.01 | Dec 1, 2022 | Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no password length limit when creating a user as an administrator. An administrator can cause a limited DoS attack against their own server. Versions 23.0.11,… | ||
| CVE-2022-3268 | Cri | 0.00 | 9.8 | 0.01 | Sep 22, 2022 | Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2. | ||
| CVE-2022-2098 | Cri | 0.00 | 9.8 | 0.01 | Jun 16, 2022 | Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1. | ||
| CVE-2022-1775 | Cri | 0.00 | 9.8 | 0.02 | May 20, 2022 | Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2. |
- risk 0.20cvss 3.1epss 0.00
A vulnerability was detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue affects some unknown processing of the file /admin/user/updatePwd. Performing manipulation results in weak password requirements. Remote exploitation of the attack is possible. A high degree of…
- risk 0.20cvss 3.1epss 0.00
IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system.
- risk 0.20cvss 3.1epss 0.01
A vulnerability, which was classified as problematic, was found in RRJ Nueva Ecija Engineer Online Portal 1.0. This affects an unknown part of the file change_password_teacher.php. The manipulation leads to weak password requirements. It is possible to initiate the attack…
- risk 0.20cvss 3.1epss 0.01
A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user/signup.php. The manipulation leads to weak password requirements. The attack can be initiated remotely. The…
- risk 0.17cvss 3.7epss 0.00
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password policy vulnerability was identified in the user management functionality of the LibreNMS application. This vulnerability allows administrators to create…
- risk 0.14cvss 2.2epss 0.00
An Unverified Password Change could allow a malicious actor with API access to the device to change the system password without knowing the previous password. Affected Products: UniFi Connect EV Station (Version 1.1.18 and earlier) UniFi Connect EV Station Pro (Version…
- risk 0.13cvss 2.0epss 0.00
A weakness has been identified in Beetel 777VR1 up to 01.00.09/01.00.09_55. This vulnerability affects unknown code of the component UART Interface. Executing a manipulation can lead to weak password requirements. The physical device can be targeted for the attack. The attack…
- risk 0.11cvss 2.7epss 0.00
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creation and editing via the REST API fails to apply the password validation rules defined by Django's AUTH_PASSWORD_VALIDATORS setting (which defaults to an empty…
- CVE-2012-2441Apr 28, 2012risk 0.04cvss —epss 0.09
RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) SSH…
- risk 0.00cvss —epss 0.00
Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a password and obtain a root shell via an…
- risk 0.00cvss 3.1epss 0.00
HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.
- risk 0.00cvss —epss 0.00
KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any alphabetic, special, or extended characters. This issue was fixed in the patch published in June 2026.
- risk 0.00cvss 7.3epss 0.00
Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time Password (OTP). Prior to version 1.0.1, even if a secure random number generator is used, the short length and limited range (1000–9999) results in only…
- risk 0.00cvss 7.5epss 0.00
CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.
- risk 0.00cvss 8.8epss 0.01
Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0.
- risk 0.00cvss 6.5epss 0.01
Kiwi TCMS is an open source test management system. In version 11.6 and prior, when users register new accounts and/or change passwords, there is no validation in place which would prevent them from picking an easy to guess password. This issue is resolved by providing defaults…
- risk 0.00cvss 2.4epss 0.01
Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no password length limit when creating a user as an administrator. An administrator can cause a limited DoS attack against their own server. Versions 23.0.11,…
- risk 0.00cvss 9.8epss 0.01
Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.
- risk 0.00cvss 9.8epss 0.01
Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.
- risk 0.00cvss 9.8epss 0.02
Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2.