VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,283)

page 65 of 115
  • CVE-2025-4119MedApr 30, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability classified as critical was found in Weitong Mall 1.0.0. This vulnerability affects unknown code of the file /queryTotal of the component Product Statistics Handler. The manipulation of the argument isDelete with the input 1 leads to improper access controls. The…

  • CVE-2025-31950MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can obtain EV charger energy consumption information of other users.

  • CVE-2025-31945MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.01

    An unauthenticated attacker can obtain other users' charger information.

  • CVE-2025-31654MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms").

  • CVE-2025-31147MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.

  • CVE-2025-30257MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account.

  • CVE-2025-27929MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts.

  • CVE-2025-27927MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.

  • CVE-2025-27719MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.01

    Unauthenticated attackers can query an API endpoint and get device details.

  • CVE-2025-27575MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID.

  • CVE-2025-27565MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.

  • CVE-2025-27561MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can rename "rooms" of arbitrary users.

  • CVE-2025-26857MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).

  • CVE-2025-25276MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can hijack other users' devices and potentially control them.

  • CVE-2025-24850MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An attacker can export other users' plant information.

  • CVE-2025-24315MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.01

    Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).

  • CVE-2025-31949MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An authenticated attacker can obtain any plant name by knowing the plant ID.

  • CVE-2025-31941MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can obtain a list of smart devices by knowing a valid username.

  • CVE-2025-31933MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can check the existence of usernames in the system by querying an API.

  • CVE-2025-31357MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can obtain a user's plant list by knowing the username.