The product does not require that users should have strong passwords.
Volume of CVEs assigned to CWE-521 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
259 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17444CRITICAL Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attac | Oct 12, 2020 | 9.8 | 79 | NO | YES |
CVE-2019-18988HIGH TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key fo | Feb 7, 2020 | 7.0 | 74 | YES | YES |
CVE-2012-2441HIGH RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes it easier for remote attackers | Apr 28, 2012 | 8.5 | 40 | NO | YES |
CVE-2024-48845CRITICAL Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access.
Affec | Dec 5, 2024 | 9.8 | 36 | NO | YES |
CVE-2026-25715CRITICAL The web management interface of the device allows the administrator
username and password to be set to blank values. Once applied, the
device permits authentication with empty cr | Feb 20, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-55252CRITICAL HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable passwords, potentially resulting in unauthorized access | Jan 19, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-63747CRITICAL QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the acc | Nov 17, 2025 | 9.8 | 33 | NO | NO |
CVE-2017-14189CRITICAL An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password. | Nov 29, 2017 | 9.8 | 33 | NO | NO |
CVE-2017-12861CRITICAL The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a unique 4-digit code, displayed on-scree | Oct 10, 2017 | 9.8 | 33 | NO | NO |
CVE-2017-6339MEDIUM Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation, by default, IWSVA acts as a pr | Apr 5, 2017 | 6.5 | 33 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.