CWE-521— Weak Password Requirements
The product does not require that users should have strong passwords.— MITRE CWE catalog
271 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-521page 2 of 6
- CVE-2021-25839CRITICALCVSS 9.8EG 9.82021-04-26
A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could lead an attacker to easier password brute-forcing.
- CVE-2021-26797CRITICALCVSS 9.8EG 9.82021-04-26
An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administrator through an open Telnet service.
- CVE-2021-25309CRITICALCVSS 9.8EG 9.82021-03-02
The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4-digit password) al…
- CVE-2020-25153CRITICALCVSS 9.8EG 9.82020-12-23
The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong passwords.
- CVE-2020-29591CRITICALCVSS 9.8EG 9.82020-12-11
Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker to achieve root access with a blank pa…
- CVE-2020-26201CRITICALCVSS 9.8EG 9.82020-12-10
Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level. This allows an attacker to gain unauthorized access as an admin or root user to the device Operating System via Telnet or…
- CVE-2019-17444CRITICALCVSS 9.8EG 9.82020-10-12
Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This is…
- CVE-2020-11624CRITICALCVSS 9.8EG 9.82020-07-23
An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. They do not require users to change the default password for the admin account…
- CVE-2019-4576CRITICALCVSS 9.8EG 9.82020-06-10
IBM QRadar Network Packet Capture 7.3.0 - 7.3.3 Patch 1 and 7.4.0 GA does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166803.
- CVE-2020-8790CRITICALCVSS 9.8EG 9.82020-05-04
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attacker to discover use…
- CVE-2017-18857CRITICALCVSS 9.8EG 9.82020-04-28
The NETGEAR Insight application before 2.42 for Android and iOS is affected by password mismanagement.
- CVE-2020-11966CRITICALCVSS 9.8EG 9.82020-04-21
In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after …
- CVE-2020-6991CRITICALCVSS 9.8EG 9.82020-03-24
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, weak password requirements may allow an attacker to gain access using brute force.
- CVE-2020-6995CRITICALCVSS 9.8EG 9.82020-03-24
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the application utilizes weak password requirements, which may allow an attacker to gain unauthorized access.
- CVE-2019-9096CRITICALCVSS 9.8EG 9.82020-03-11
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Insufficient password requirements for the MGate web application ma…
- CVE-2020-9023CRITICALCVSS 9.8EG 9.82020-02-17
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetooth is the root pass…
- CVE-2019-7488CRITICALCVSS 9.8EG 9.82019-12-23
Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.
- CVE-2019-19747CRITICALCVSS 9.8EG 9.82019-12-20
NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid usern…
- CVE-2019-19690CRITICALCVSS 9.8EG 9.82019-12-18
Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass the product's App Password Protection feature.
- CVE-2019-3758CRITICALCVSS 9.8EG 9.82019-09-18
RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized a…
- CVE-2019-13918CRITICALCVSS 9.8EG 9.82019-09-13
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with network access to …
- CVE-2019-9950CRITICALCVSS 9.8EG 9.82019-04-24
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an authentication bypass vu…
- CVE-2019-9123CRITICALCVSS 9.8EG 9.82019-02-25
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. The "user" account has a blank password.
- CVE-2019-7674CRITICALCVSS 9.8EG 9.82019-02-09
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. /admin/access accepts a request to set the "aaaaa" password, considered insecure for some use cases, from a user.
- CVE-2018-15719CRITICALCVSS 9.8EG 9.82018-12-12
Open Dental before version 18.4 installs a mysql database and uses the default credentials of "root" with a blank password. This allows anyone on the network with access to the server to access all database information.
- CVE-2018-19064CRITICALCVSS 9.8EG 9.82018-11-07
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ftpuser1 account has a blank passw…
- CVE-2018-12925CRITICALCVSS 9.8EG 9.82018-06-28
Baseon Lantronix MSS devices do not require a password for TELNET access.
- CVE-2017-1601CRITICALCVSS 9.8EG 9.82018-05-02
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132…
- CVE-2018-1000134CRITICALCVSS 9.8EG 9.82018-03-16
UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where the issue was reported and fixed contains an Incorrect Access Control vulnerability in process fun…
- CVE-2018-1372CRITICALCVSS 9.8EG 9.82018-02-27
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 137772.
- CVE-2017-3186CRITICALCVSS 9.8EG 9.82017-12-16
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all devices. A remote attacker can take complete control of a device using default admin credentials.
- CVE-2017-14189CRITICALCVSS 9.8EG 9.82017-11-29
An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password.
- CVE-2017-1221CRITICALCVSS 9.8EG 9.82017-11-13
IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123861.
- CVE-2017-12861CRITICALCVSS 9.8EG 9.82017-10-10
The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a unique 4-digit code, displayed on-screen - ensuring only those who can view it are streaming.All E…
- CVE-2017-9853CRITICALCVSS 9.8EG 9.82017-08-05
An issue was discovered in SMA Solar Technology products. All inverters have a very weak password policy for the user and installer password. No complexity requirements or length requirements are set. Also, strong passwords are impossible …
- CVE-2017-7903CRITICALCVSS 9.8EG 9.82017-06-30
A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00…
- CVE-2017-1196CRITICALCVSS 9.8EG 9.82017-06-07
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123671.
- CVE-2022-1039CRITICALCVSS 9.6EG 9.82022-04-20
The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the other passwords can be changed. The weak password on Linux accounts can be accessed via SSH or Telnet, the former of wh…
- CVE-2025-25737CRITICALCVSS 6.8EG 9.82025-08-26
Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack secure password requirements for its BIOS Supervisor and User accounts, allowing attackers to bypass auth…
- CVE-2025-55299CRITICALCVSS 9.4EG 9.42025-08-18
VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through the User web UI have an empty but not NULL password set, attackers can use this to login with an empty password. This i…
- CVE-2024-48845CRITICALCVSS 9.4EG 9.42024-12-05
Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access. Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS S…
- CVE-2026-6284CRITICALCVSS 9.1EG 9.12026-04-17
An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiters makes brute force password enumeration…
- CVE-2026-27575CRITICALCVSS 9.1EG 9.12026-02-25
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength requirements. Additionally, active session…
- CVE-2017-16727CRITICALCVSS 9.1EG 9.12017-12-22
A Credentials Management issue was discovered in Moxa NPort W2150A versions prior to 1.11, and NPort W2250A versions prior to 1.11. The default password is empty on the device. An unauthorized user can access the device without a password.…
- CVE-2025-26847CRITICALCVSS 7.5EG 9.12025-05-08
An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.
- CVE-2023-0641CRITICALCVSS 3.7EG 9.12023-02-02
A vulnerability was found in PHPGurukul Employee Leaves Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file changepassword.php. The manipulation of the argument…
- CVE-2021-40333CRITICALCVSS 9.0EG 9.02021-12-02
Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Network (DCN) routing configuration. This issue affects: Hitachi Energy FOX61x versions prior…
- CVE-2026-19293HIGHCVSS 8.8EG 8.82026-08-13
SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less than the maximum keysize makes brute-forcing the key easier. See V6 in BLERP paper linked below.
- CVE-2026-41038HIGHCVSS 8.8EG 8.82026-04-21
This vulnerability exists in Quantum Networks router due to lack of enforcement of strong password policies in the web-based management interface. An attacker on the same network could exploit this vulnerability by performing password gues…
- CVE-2024-48271HIGHCVSS 8.8EG 8.82024-10-30
D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers to bypass authentication and escalate privileges on the device via a bruteforce attack.
Map vulnerabilities like CWE-521 to your infrastructure
EchelonGraph correlates every CVE — across CWE-521 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →