CWE-521— Weak Password Requirements
The product does not require that users should have strong passwords.— MITRE CWE catalog
271 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-521page 1 of 6
- CVE-2019-18988CRITICALCVSS 7.0EG 9.0⚠ KEV2020-02-07
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key for all installations since at least as far back as v7.0.4314…
- CVE-2026-85216CRITICALCVSS 9.8EG 9.82026-09-03
MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakeP…
- CVE-2026-73778CRITICALCVSS 9.8EG 9.82026-09-01
A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state befo…
- CVE-2024-40684CRITICALCVSS 9.8EG 9.82026-05-27
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users sh…
- CVE-2025-55269CRITICALCVSS 9.8EG 9.82026-03-26
HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts.
- CVE-2026-25715CRITICALCVSS 9.8EG 9.82026-02-20
The web management interface of the device allows the administrator username and password to be set to blank values. Once applied, the device permits authentication with empty credentials over the web management interface and Telnet ser…
- CVE-2025-55252CRITICALCVSS 9.8EG 9.82026-01-19
HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable passwords, potentially resulting in unauthorized access
- CVE-2025-53963CRITICALCVSS 9.8EG 9.82025-12-04
An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The root account has a weak default password of ionadmin, and a password change policy for the …
- CVE-2025-63747CRITICALCVSS 9.8EG 9.82025-11-17
QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the account provides administrative privileges in the default conf…
- CVE-2025-12552CRITICALCVSS 9.8EG 9.82025-10-31
Insufficient Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- CVE-2025-11200CRITICALCVSS 9.8EG 9.82025-10-29
MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. …
- CVE-2025-12364CRITICALCVSS 9.8EG 9.82025-10-27
Weak Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- CVE-2025-12285CRITICALCVSS 9.8EG 9.82025-10-26
Missing Initial Password Change.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- CVE-2025-30127CRITICALCVSS 9.8EG 9.82025-08-06
An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings (containing sensitive routes, conversations, and footage) are open for downloadi…
- CVE-2025-28389CRITICALCVSS 9.8EG 9.82025-06-13
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.
- CVE-2025-28200CRITICALCVSS 9.8EG 9.82025-05-09
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.
- CVE-2025-25211CRITICALCVSS 9.8EG 9.82025-03-31
Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker unauthorized access and login.
- CVE-2025-27663CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Weak Password Encryption / Encoding OVE-20230524-0007.
- CVE-2024-42850CRITICALCVSS 9.8EG 9.82024-08-16
An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.
- CVE-2024-3263CRITICALCVSS 9.8EG 9.82024-05-14
YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of improper method for system credentials generation and weak password policy, passwords can be easily guessed and en…
- CVE-2023-49238CRITICALCVSS 9.8EG 9.82024-01-09
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Although this password must be changed upon th…
- CVE-2023-24049CRITICALCVSS 9.8EG 9.82023-12-04
An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credential management.
- CVE-2023-29974CRITICALCVSS 9.8EG 9.82023-11-08
An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.
- CVE-2023-37756CRITICALCVSS 9.8EG 9.82023-09-14
I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easily guess users' passwords via a bruteforce attack.
- CVE-2023-31098CRITICALCVSS 9.8EG 9.82023-05-22
Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0. When users change their password to a simple password (with any character or symbol), attac…
- CVE-2023-2106CRITICALCVSS 9.8EG 9.82023-04-15
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20.
- CVE-2022-32513CRITICALCVSS 9.8EG 9.82023-01-30
A CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker brute forces the password. Affected Products: C-Bus Network Automation Controller - LSS5500NAC (Version…
- CVE-2023-0307CRITICALCVSS 9.8EG 9.82023-01-15
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.10.
- CVE-2022-44236CRITICALCVSS 9.8EG 9.82022-12-15
Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) has a Weak password vulnerability.
- CVE-2022-45482CRITICALCVSS 9.8EG 9.82022-12-02
Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H…
- CVE-2022-3754CRITICALCVSS 9.8EG 9.82022-10-29
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
- CVE-2022-3268CRITICALCVSS 9.8EG 9.82022-09-22
Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.
- CVE-2022-37164CRITICALCVSS 9.8EG 9.82022-09-08
Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much ea…
- CVE-2022-37163CRITICALCVSS 9.8EG 9.82022-09-08
Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making …
- CVE-2022-37158CRITICALCVSS 9.8EG 9.82022-08-25
RuoYi v3.8.3 has a Weak password vulnerability in the management system.
- CVE-2022-2927CRITICALCVSS 9.8EG 9.82022-08-22
Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7.
- CVE-2022-34615CRITICALCVSS 9.8EG 9.82022-08-19
Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks.
- CVE-2022-35280CRITICALCVSS 9.8EG 9.82022-08-10
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634.
- CVE-2022-35143CRITICALCVSS 9.8EG 9.82022-08-04
Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks.
- CVE-2022-36301CRITICALCVSS 9.8EG 9.82022-08-01
BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password.
- CVE-2022-31211CRITICALCVSS 9.8EG 9.82022-07-17
An issue was discovered in Infiray IRAY-A8Z3 1.0.957. There is a blank root password for TELNET by default.
- CVE-2022-1668CRITICALCVSS 9.8EG 9.82022-06-24
Weak default root user credentials allow remote attackers to easily obtain OS superuser privileges over the open TCP port for SSH.
- CVE-2022-2098CRITICALCVSS 9.8EG 9.82022-06-16
Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.
- CVE-2022-1775CRITICALCVSS 9.8EG 9.82022-05-20
Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2.
- CVE-2021-43036CRITICALCVSS 9.8EG 9.82021-12-06
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.
- CVE-2021-40520CRITICALCVSS 9.8EG 9.82021-11-10
Airangel HSMX Gateway devices through 5.2.04 have Weak SSH Credentials.
- CVE-2021-38462CRITICALCVSS 9.8EG 9.82021-10-19
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This may allow an attacker with obtained user credentials to enumerate passwords and impersonate other application users and…
- CVE-2021-35498CRITICALCVSS 9.8EG 9.82021-10-13
The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, and TIBCO Product and Service Catalog powered by TIBCO EBX contains a vulnerability that under certain specific conditions allows an attacker to e…
- CVE-2021-41296CRITICALCVSS 9.8EG 9.82021-09-30
ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.
- CVE-2021-20418CRITICALCVSS 9.8EG 9.82021-08-11
IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196279.
Map vulnerabilities like CWE-521 to your infrastructure
EchelonGraph correlates every CVE — across CWE-521 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →