CWE-639
Authorization Bypass Through User-Controlled Key
Description
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Hierarchy (View 1000)
CVEs mapped to this weakness (2,283)
page 65 of 115| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-4119 | Med | 0.34 | 5.3 | 0.01 | Apr 30, 2025 | A vulnerability classified as critical was found in Weitong Mall 1.0.0. This vulnerability affects unknown code of the file /queryTotal of the component Product Statistics Handler. The manipulation of the argument isDelete with the input 1 leads to improper access controls. The… | ||
| CVE-2025-31950 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can obtain EV charger energy consumption information of other users. | ||
| CVE-2025-31945 | Med | 0.34 | 5.3 | 0.01 | Apr 15, 2025 | An unauthenticated attacker can obtain other users' charger information. | ||
| CVE-2025-31654 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms"). | ||
| CVE-2025-31147 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users. | ||
| CVE-2025-30257 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account. | ||
| CVE-2025-27929 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts. | ||
| CVE-2025-27927 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API. | ||
| CVE-2025-27719 | Med | 0.34 | 5.3 | 0.01 | Apr 15, 2025 | Unauthenticated attackers can query an API endpoint and get device details. | ||
| CVE-2025-27575 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID. | ||
| CVE-2025-27565 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs. | ||
| CVE-2025-27561 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | Unauthenticated attackers can rename "rooms" of arbitrary users. | ||
| CVE-2025-26857 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers). | ||
| CVE-2025-25276 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can hijack other users' devices and potentially control them. | ||
| CVE-2025-24850 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An attacker can export other users' plant information. | ||
| CVE-2025-24315 | Med | 0.34 | 5.3 | 0.01 | Apr 15, 2025 | Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users). | ||
| CVE-2025-31949 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An authenticated attacker can obtain any plant name by knowing the plant ID. | ||
| CVE-2025-31941 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can obtain a list of smart devices by knowing a valid username. | ||
| CVE-2025-31933 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can check the existence of usernames in the system by querying an API. | ||
| CVE-2025-31357 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can obtain a user's plant list by knowing the username. |
- risk 0.34cvss 5.3epss 0.01
A vulnerability classified as critical was found in Weitong Mall 1.0.0. This vulnerability affects unknown code of the file /queryTotal of the component Product Statistics Handler. The manipulation of the argument isDelete with the input 1 leads to improper access controls. The…
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can obtain EV charger energy consumption information of other users.
- risk 0.34cvss 5.3epss 0.01
An unauthenticated attacker can obtain other users' charger information.
- risk 0.34cvss 5.3epss 0.00
An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms").
- risk 0.34cvss 5.3epss 0.00
Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.
- risk 0.34cvss 5.3epss 0.01
Unauthenticated attackers can query an API endpoint and get device details.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated attackers can rename "rooms" of arbitrary users.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can hijack other users' devices and potentially control them.
- risk 0.34cvss 5.3epss 0.00
An attacker can export other users' plant information.
- risk 0.34cvss 5.3epss 0.01
Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).
- risk 0.34cvss 5.3epss 0.00
An authenticated attacker can obtain any plant name by knowing the plant ID.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can obtain a list of smart devices by knowing a valid username.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can check the existence of usernames in the system by querying an API.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can obtain a user's plant list by knowing the username.