CWE-521— Weak Password Requirements
The product does not require that users should have strong passwords.— MITRE CWE catalog
271 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-521page 3 of 6
- CVE-2024-25729HIGHCVSS 8.8EG 8.82024-03-08
Arris SBG6580 devices have predictable default WPA2 security passwords that could lead to unauthorized remote access. (They use the first 6 characters of the SSID and the last 6 characters of the BSSID, decrementing the last octet.)
- CVE-2023-7053HIGHCVSS 8.8EG 8.82023-12-22
A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user/signup.php. The manipulation leads to weak password requirements. The a…
- CVE-2023-41353HIGHCVSS 8.8EG 8.82023-11-03
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin a…
- CVE-2023-4125HIGHCVSS 8.8EG 8.82023-08-03
Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.
- CVE-2023-3423HIGHCVSS 8.8EG 8.82023-06-27
Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0.
- CVE-2022-3179HIGHCVSS 8.8EG 8.82022-09-13
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2.
- CVE-2022-26117HIGHCVSS 8.8EG 8.82022-07-18
An empty password in configuration file vulnerability [CWE-258] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.3 and below may allow an authentic…
- CVE-2022-30325HIGHCVSS 8.8EG 8.82022-06-16
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The default pre-shared key for the Wi-Fi networks is the same for every router except for the last four digits. The device default pre-shared key for both 2.4 GHz and 5 G…
- CVE-2020-11925HIGHCVSS 8.8EG 8.82021-04-02
An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The root credentials are the same across all devices of this model.
- CVE-2020-15369HIGHCVSS 8.8EG 8.82020-09-25
Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credentials of the remote server. An authenticated user could obtain…
- CVE-2018-18562HIGHCVSS 8.8EG 8.82018-11-20
An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04 and CoaguChek / cobas h232 Handheld Base Unit before 03.01.04. Weak access credentials may enable attackers in the adjacent network to gain unau…
- CVE-2018-17906HIGHCVSS 8.8EG 8.82018-11-19
Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of the system.
- CVE-2018-15748HIGHCVSS 8.8EG 8.82018-08-23
On Dell 2335dn printers with Printer Firmware Version 2.70.05.02, Engine Firmware Version 1.10.65, and Network Firmware Version V4.02.15(2335dn MFP) 11-22-2010, the admin interface allows an authenticated attacker to retrieve the configure…
- CVE-2022-34772HIGHCVSS 4.3EG 8.82022-08-22
Tabit - password enumeration. Description: Tabit - password enumeration. The passwords for the Tabit system is a 4 digit OTP. One can resend OTP and try logging in indefinitely. Once again, this is an example of OWASP: API4 - Rate limiting.
- CVE-2025-34058HIGHCVSS 8.7EG 8.72025-07-01
Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary …
- CVE-2025-9964HIGHCVSS 8.6EG 8.62025-09-23
No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console easily. This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9…
- CVE-2023-40707HIGHCVSS 8.6EG 8.62023-08-24
There are no requirements for setting a complex password in the built-in web server of the SNAP PAC S1 Firmware version R10.3b, which could allow for a successful brute force attack if users don't set up complex credentials.
- CVE-2012-2441HIGHCVSS v2 8.5EG 8.52012-04-28
RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes it easier for remote attackers to obtain access by performing a calculation on this addres…
- CVE-2026-12504HIGHCVSS 8.4EG 8.42026-07-24
Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a passwor…
- CVE-2025-68716HIGHCVSS 8.4EG 8.42026-01-08
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configured with no password, and administrators cannot disable SSH or enforce authentication via the CLI o…
- CVE-2025-60954HIGHCVSS 8.3EG 8.32025-10-24
Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead …
- CVE-2021-32753HIGHCVSS 8.3EG 8.32021-07-09
EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vulnerability exists in the Edinburgh, Fuji, Geneva, and Hanoi versions of the software. When the EdgeX API gateway is co…
- CVE-2025-55034HIGHCVSS 8.2EG 8.22025-11-15
General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login.
- CVE-2026-33771HIGHCVSS 8.1EG 8.12026-04-09
A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control …
- CVE-2024-36789HIGHCVSS 8.1EG 8.12024-06-07
An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards.
- CVE-2024-0188HIGHCVSS 8.1EG 8.12024-01-02
A vulnerability, which was classified as problematic, was found in RRJ Nueva Ecija Engineer Online Portal 1.0. This affects an unknown part of the file change_password_teacher.php. The manipulation leads to weak password requirements. It i…
- CVE-2023-37503HIGHCVSS 8.1EG 8.12023-10-19
HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.
- CVE-2022-29098HIGHCVSS 8.1EG 8.12022-06-01
Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an account with no password. A remote attacker may potentially exploit this leading to a user account co…
- CVE-2021-25923HIGHCVSS 8.1EG 8.12021-06-24
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leve…
- CVE-2025-57295HIGHCVSS 8.0EG 8.02025-09-18
H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user account has no password set, and the H3C user account uses the default password "admin," both stored…
- CVE-2022-39997HIGHCVSS 8.0EG 8.02024-08-27
A weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privileges
- CVE-2025-63800HIGHCVSS 7.5EG 7.52025-11-18
The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_pass…
- CVE-2025-22390HIGHCVSS 7.5EG 7.52025-01-04
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficient enforcement of password complexity requirements. The application permits users to set passwords …
- CVE-2024-7293HIGHCVSS 7.5EG 7.52024-10-09
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.
- CVE-2024-47221HIGHCVSS 7.5EG 7.52024-09-22
CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.
- CVE-2024-40697HIGHCVSS 7.5EG 7.52024-08-13
IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 297895.
- CVE-2023-34995HIGHCVSS 7.5EG 7.52023-07-07
There are no requirements for setting a complex password for PiiGAB M-Bus, which could contribute to a successful brute force attack if the password is inline with recommended password guidelines.
- CVE-2023-2060HIGHCVSS 7.5EG 7.52023-06-02
Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to a…
- CVE-2023-25184HIGHCVSS 7.5EG 7.52023-05-10
Use of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. Affected products and versions are as follows: SkyBridge …
- CVE-2023-25072HIGHCVSS 7.5EG 7.52023-05-10
Use of weak credentials exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product.
- CVE-2023-31043HIGHCVSS 7.5EG 7.52023-04-23
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_c…
- CVE-2023-24502HIGHCVSS 7.5EG 7.52023-04-17
Electra Central AC unit – The unit opens an AP with an easily calculated password.
- CVE-2022-45635HIGHCVSS 7.5EG 7.52023-03-21
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to gain access to sensitive account information via insecure password policy.
- CVE-2021-39434HIGHCVSS 7.5EG 7.52022-12-06
A default username and password for an administrator account was discovered in ZKTeco ZKTime 10.0 through 11.1.0, builds 20180901, 20190510.1, 20200309.3, 20200930, 20201231, and 20210220.
- CVE-2022-35198HIGHCVSS 7.5EG 7.52022-08-18
Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information.
- CVE-2022-28377HIGHCVSS 7.5EG 7.52022-07-14
On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static account username/password for access control. This password can be generated via a binary incl…
- CVE-2022-29729HIGHCVSS 7.5EG 7.52022-06-02
Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.
- CVE-2022-29700HIGHCVSS 7.5EG 7.52022-04-27
A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cause a Denial of Service (DoS) during password verification.
- CVE-2021-38935HIGHCVSS 7.5EG 7.52022-02-18
IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 210892.
- CVE-2022-22110HIGHCVSS 7.5EG 7.52022-01-05
In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his password could change it to a weak password, such as those with a length of a single char…
Map vulnerabilities like CWE-521 to your infrastructure
EchelonGraph correlates every CVE — across CWE-521 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →