CWE-521— Weak Password Requirements
The product does not require that users should have strong passwords.— MITRE CWE catalog
271 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-521page 6 of 6
- CVE-2017-7305MEDIUMCVSS 4.6EG 4.62017-04-04
Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism via a crafted boot. NOTE: the vendor believes that this does not m…
- CVE-2020-27585MEDIUMCVSS 4.4EG 4.42020-11-30
Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on the settings password.
- CVE-2026-34203MEDIUMCVSS 4.3EG 4.32026-03-31
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creation and editing via the REST API fails to apply the password validation rules defined by Django's AUTH_PASSWORD_VALIDATOR…
- CVE-2025-46742MEDIUMCVSS 4.3EG 4.32025-05-12
Users who were required to change their password could still access system information before changing their password
- CVE-2022-3326MEDIUMCVSS 4.3EG 4.32022-09-29
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.9.
- CVE-2021-1522MEDIUMCVSS 4.3EG 4.32021-08-04
A vulnerability in the change password API of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, remote attacker to alter their own password to a value that does not comply with the strong authentication requirements th…
- CVE-2026-1408MEDIUMCVSS 4.2EG 4.22026-01-25
A weakness has been identified in Beetel 777VR1 up to 01.00.09/01.00.09_55. This vulnerability affects unknown code of the component UART Interface. Executing a manipulation can lead to weak password requirements. The physical device can b…
- CVE-2025-65014LOWCVSS 3.7EG 3.72025-11-18
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password policy vulnerability was identified in the user management functionality of the LibreNMS application. This vulnerabilit…
- CVE-2025-11322LOWCVSS 3.7EG 3.72025-10-06
A flaw has been found in Mangati NovoSGA up to 2.2.12. The impacted element is an unknown function of the file /novosga.users/new of the component User Creation Page. Executing manipulation of the argument Senha/Confirmação da senha can …
- CVE-2025-9514LOWCVSS 3.7EG 3.72025-08-27
A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the component Registration. Such manipulation leads to weak password requirements. The attack can be executed remotely. Attacks of this natu…
- CVE-2025-8549LOWCVSS 3.7EG 3.72025-08-05
A vulnerability was found in atjiu pybbs up to 6.0.0. It has been classified as critical. Affected is the function update of the file src/main/java/co/yiiu/pybbs/controller/admin/UserAdminController.java. The manipulation leads to weak pas…
- CVE-2025-4534LOWCVSS 3.7EG 3.72025-05-11
A vulnerability, which was classified as problematic, has been found in SunGrow Logger1000 01_A. This issue affects some unknown processing. The manipulation leads to weak password requirements. The attack may be initiated remotely. The co…
- CVE-2025-1341LOWCVSS 3.7EG 3.72025-02-16
A vulnerability, which was classified as problematic, was found in PMWeb 7.2.0. This affects an unknown part of the component Setting Handler. The manipulation leads to weak password requirements. It is possible to initiate the attack remo…
- CVE-2024-3735LOWCVSS 3.7EG 3.72024-04-13
A vulnerability was found in Smart Office up to 20240405. It has been classified as problematic. Affected is an unknown function of the file Main.aspx. The manipulation of the argument New Password/Confirm Password with the input 1 leads t…
- CVE-2024-0347LOWCVSS 3.7EG 3.72024-01-09
A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as problematic. This issue affects some unknown processing of the file signup_teacher.php. The manipulation of the argument Password leads to weak passw…
- CVE-2020-8956LOWCVSS 3.3EG 3.32020-10-27
Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.
- CVE-2026-9394LOWCVSS 3.1EG 3.12026-05-24
A vulnerability was determined in Besen BS20 EV Charging Station up to 20260426. This impacts an unknown function of the component Bluetooth Low Energy Handler. Executing a manipulation can lead to weak password requirements. The attack ne…
- CVE-2025-10320LOWCVSS 3.1EG 3.12025-09-12
A vulnerability was detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue affects some unknown processing of the file /admin/user/updatePwd. Performing manipulation results in weak password requirements. Remote exploitation of the at…
- CVE-2023-27272LOWCVSS 3.1EG 3.12025-04-14
IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system.
- CVE-2022-41969LOWCVSS 2.4EG 2.42022-12-01
Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no password length limit when creating a user as an administrator. An administrator can cause a limited DoS attack against th…
- CVE-2024-29208LOWCVSS 2.2EG 2.22024-05-07
An Unverified Password Change could allow a malicious actor with API access to the device to change the system password without knowing the previous password. Affected Products: UniFi Connect EV Station (Version 1.1.18 and earlier) …
Map vulnerabilities like CWE-521 to your infrastructure
EchelonGraph correlates every CVE — across CWE-521 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →