Threats Tagged 'cwe-521'
View all threats tagged with 'cwe-521'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-521'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-73778 is a high-severity vulnerability in Hewlett Packard Enterprise (HPE) AOS-CX's Credential Manager component. It allows an unauthenticated remote attacker to gain unauthorized administrative access by exploiting a predictable factory-default password during the device's initial setup state (factory-default or post-ZTP) before any administrator credentials are configured. Successful exploitation grants full administrative control over the affected device during initial setup. Join the discussion | GCVE Database | 09/01/2026, 20:28:53 UTC Added: 09/02/2026, 15:49:10 UTC |
SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less than the maximum keysize makes brute-forcing the key easier. See V6 in BLERP paper linked below. Join the discussion | CVE Database V5 | 08/13/2026, 14:18:05 UTC Added: 08/13/2026, 15:12:03 UTC |
CVE-2026-12504 is a high-severity improper authentication vulnerability in the PAM configuration of Loytec LIP-ME20xC devices and related products up to version 8.4.16 on LINX-A64. It allows a local attacker to authenticate as the root user without a password by exploiting an /etc/passwd entry with an empty password field, resulting in root shell access. Join the discussion | CVE Database V5 | 07/24/2026, 13:58:16 UTC Added: 07/24/2026, 14:37:56 UTC |
HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks. Join the discussion | CVE Database V5 | 07/21/2026, 17:32:56 UTC Added: 07/21/2026, 17:42:22 UTC |
KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any alphabetic, special, or extended characters. This issue was fixed in the patch published in June 2026. Join the discussion | CVE Database V5 | 06/30/2026, 13:37:57 UTC Added: 06/30/2026, 14:06:52 UTC |
0 IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. Join the discussion | CVE Database V5 | 05/27/2026, 13:48:59 UTC Added: 05/27/2026, 14:03:57 UTC |
0 This vulnerability exists in Quantum Networks router due to lack of enforcement of strong password policies in the web-based management interface. An attacker on the same network could exploit this vulnerability by performing password guessing or brute-force attacks against user accounts, leading to unauthorized access to the targeted device. Join the discussion | CVE Database V5 | 04/21/2026, 10:22:09 UTC Added: 04/21/2026, 10:46:05 UTC |
0 An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiters makes brute force password enumeration possible. Join the discussion | CVE Database V5 | 04/17/2026, 15:14:06 UTC Added: 04/17/2026, 15:38:11 UTC |
A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device. The password management menu enables the administrator to set password complexity requirements, but these settings are not saved. The issue can be verified with the menu option "Show password requirements". Failure to enforce the intended requirements can lead to weak passwords being used, which significantly increases the likelihood that an attacker can guess these and subsequently attain unauthorized access. This issue affects CTP OS versions 9.2R1 and 9.2R2. Join the discussion | CVE Database V5 | 04/09/2026, 21:33:57 UTC Added: 04/09/2026, 22:05:49 UTC |
HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts. Join the discussion | CVE Database V5 | 03/26/2026, 13:00:31 UTC Added: 03/26/2026, 13:16:15 UTC |
Showing 1 to 10 of 26 results