CWE-521— Weak Password Requirements
The product does not require that users should have strong passwords.— MITRE CWE catalog
268 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-521page 5 of 6
- CVE-2024-41683MEDIUMCVSS 5.3EG 5.32024-08-13
A vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not properly enforce a strong user password policy. This could facilitate a brute force attack against legitimate user password…
- CVE-2024-41778MEDIUMCVSS 5.3EG 5.32025-03-01
IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
- CVE-2024-42173MEDIUMCVSS 4.8EG 4.82025-01-11
HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force passwords if the username is known.
- CVE-2024-42850CRITICALCVSS 9.8EG 9.82024-08-16
An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.
- CVE-2024-45374MEDIUMCVSS 5.3EG 5.32024-09-26
The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt …
- CVE-2024-47121MEDIUMCVSS 5.3EG 6.52024-09-26
The goTenna Pro App uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and u…
- CVE-2024-47221HIGHCVSS 7.5EG 7.52024-09-22
CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.
- CVE-2024-48271HIGHCVSS 8.8EG 8.82024-10-30
D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers to bypass authentication and escalate privileges on the device via a bruteforce attack.
- CVE-2024-48272MEDIUMCVSS 6.5EG 6.52024-10-30
D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers to connect to the device via a bruteforce attack.
- CVE-2024-48845CRITICALCVSS 9.4EG 9.42024-12-05
Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access. Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS S…
- CVE-2024-51398MEDIUMCVSS 6.5EG 6.52024-11-01
Altai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password leakage in the background may lead to unauthorized access, data theft, and network attacks, seriously threatening network security.
- CVE-2024-7293HIGHCVSS 7.5EG 7.52024-10-09
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.
- CVE-2025-10320LOWCVSS 3.1EG 3.12025-09-12
A vulnerability was detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue affects some unknown processing of the file /admin/user/updatePwd. Performing manipulation results in weak password requirements. Remote exploitation of the at…
- CVE-2025-11200CRITICALCVSS 9.8EG 9.82025-10-29
MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. …
- CVE-2025-11322LOWCVSS 3.7EG 3.72025-10-06
A flaw has been found in Mangati NovoSGA up to 2.2.12. The impacted element is an unknown function of the file /novosga.users/new of the component User Creation Page. Executing manipulation of the argument Senha/Confirmação da senha can …
- CVE-2025-12285CRITICALCVSS 9.8EG 9.82025-10-26
Missing Initial Password Change.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- CVE-2025-12364CRITICALCVSS 9.8EG 9.82025-10-27
Weak Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- CVE-2025-12552CRITICALCVSS 9.8EG 9.82025-10-31
Insufficient Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- CVE-2025-1341LOWCVSS 3.7EG 3.72025-02-16
A vulnerability, which was classified as problematic, was found in PMWeb 7.2.0. This affects an unknown part of the component Setting Handler. The manipulation leads to weak password requirements. It is possible to initiate the attack remo…
- CVE-2025-1474MEDIUMCVSS 5.5EG 5.52025-03-20
In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally…
- CVE-2025-1993MEDIUMCVSS 5.1EG 5.12025-05-09
IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flo…
- CVE-2025-22390HIGHCVSS 7.5EG 7.52025-01-04
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficient enforcement of password complexity requirements. The application permits users to set passwords …
- CVE-2025-23408MEDIUMCVSS 6.5EG 6.52025-12-12
Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.0. Users are encouraged to upgrade to version 1.13.0, the latest release.
- CVE-2025-25211CRITICALCVSS 9.8EG 9.82025-03-31
Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker unauthorized access and login.
- CVE-2025-25737CRITICALCVSS 6.8EG 9.82025-08-26
Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack secure password requirements for its BIOS Supervisor and User accounts, allowing attackers to bypass auth…
- CVE-2025-25749HIGHCVSS 7.1EG 7.12025-03-11
An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies.
- CVE-2025-26847CRITICALCVSS 7.5EG 9.12025-05-08
An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.
- CVE-2025-27663CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Weak Password Encryption / Encoding OVE-20230524-0007.
- CVE-2025-28200CRITICALCVSS 9.8EG 9.82025-05-09
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.
- CVE-2025-28389CRITICALCVSS 9.8EG 9.82025-06-13
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.
- CVE-2025-30127CRITICALCVSS 9.8EG 9.82025-08-06
An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings (containing sensitive routes, conversations, and footage) are open for downloadi…
- CVE-2025-34058HIGHCVSS 8.7EG 8.72025-07-01
Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary …
- CVE-2025-4534LOWCVSS 3.7EG 3.72025-05-11
A vulnerability, which was classified as problematic, has been found in SunGrow Logger1000 01_A. This issue affects some unknown processing. The manipulation leads to weak password requirements. The attack may be initiated remotely. The co…
- CVE-2025-46742MEDIUMCVSS 4.3EG 4.32025-05-12
Users who were required to change their password could still access system information before changing their password
- CVE-2025-48372HIGHCVSS 7.3EG 7.32025-05-22
Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time Password (OTP). Prior to version 1.0.1, even if a secure random number generator is used, the short length and limited…
- CVE-2025-5022MEDIUMCVSS 6.5EG 6.52025-07-10
Weak Password Requirements vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows an attacker within the Wi-Fi communication range between th…
- CVE-2025-52997MEDIUMCVSS 5.9EG 5.92025-06-30
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the auth…
- CVE-2025-53963CRITICALCVSS 9.8EG 9.82025-12-04
An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The root account has a weak default password of ionadmin, and a password change policy for the …
- CVE-2025-55034HIGHCVSS 8.2EG 8.22025-11-15
General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login.
- CVE-2025-55252LOWCVSS 9.8EG 3.12026-01-19
HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable passwords, potentially resulting in unauthorized access
- CVE-2025-55269CRITICALCVSS 9.8EG 9.82026-03-26
HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts.
- CVE-2025-55299CRITICALCVSS 9.4EG 9.42025-08-18
VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through the User web UI have an empty but not NULL password set, attackers can use this to login with an empty password. This i…
- CVE-2025-57295HIGHCVSS 8.0EG 8.02025-09-18
H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user account has no password set, and the H3C user account uses the default password "admin," both stored…
- CVE-2025-60954HIGHCVSS 8.3EG 8.32025-10-24
Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead …
- CVE-2025-63747CRITICALCVSS 9.8EG 9.82025-11-17
QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the account provides administrative privileges in the default conf…
- CVE-2025-63800HIGHCVSS 7.5EG 7.52025-11-18
The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_pass…
- CVE-2025-65014LOWCVSS 3.7EG 3.72025-11-18
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password policy vulnerability was identified in the user management functionality of the LibreNMS application. This vulnerabilit…
- CVE-2025-67513MEDIUMCVSS 6.9EG 6.92025-12-10
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forc…
- CVE-2025-68716HIGHCVSS 8.4EG 8.42026-01-08
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configured with no password, and administrators cannot disable SSH or enforce authentication via the CLI o…
- CVE-2025-68963MEDIUMCVSS 5.3EG 5.72026-01-14
Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Map vulnerabilities like CWE-521 to your infrastructure
EchelonGraph correlates every CVE — across CWE-521 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →