The product uses an IP address for authentication.
Volume of CVEs assigned to CWE-291 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-4252CRITICAL A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on i | Mar 16, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-34202HIGH Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 25.2.169 and Application prior to 25.2.1518 (VA and SaaS deployments) expose Docker internal networks in a way | Sep 19, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-66602CRITICAL A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.
The web server accepts
access by IP address. When a worm that randomly searches for IP ad | Feb 9, 2026 | 9.8 | 27 | NO | NO |
CVE-2024-23309HIGH The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on client IP addresses for authentication. Atta | Oct 30, 2024 | 8.1 | 26 | NO | NO |
CVE-2026-3690HIGH OpenClaw Canvas Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of OpenClaw. Authentication is no | Apr 11, 2026 | 7.4 | 24 | NO | NO |
CVE-2025-59101HIGH Instead of typical session tokens or cookies, it is verified on a per-request basis if the originating IP address has once successfully logged in. As soon as an authentication requ | Jan 26, 2026 | 7.7 | 24 | NO | NO |
CVE-2023-7211HIGH A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown code of the component Administrative Web Interface. The manipul | Jan 7, 2024 | 8.1 | 22 | NO | NO |
CVE-2022-46415MEDIUM DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool. To accomplish this, the attacker would first need to | Mar 27, 2023 | 5.9 | 20 | NO | NO |
CVE-2023-35906HIGH IBM Aspera Faspex 5.0.5 could allow a remote attacked to bypass IP restrictions due to improper access controls. IBM X-Force ID: 259649. | Sep 5, 2023 | 7.5 | 19 | NO | NO |
CVE-2024-32765MEDIUM A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and execute c | Aug 12, 2024 | 4.2 | 16 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.