The product uses a protection mechanism whose strength depends heavily on its obscurity, such that knowledge of its algorithms or key data is sufficient to defeat the mechanism.
Volume of CVEs assigned to CWE-656 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42363CRITICAL An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to crede | Apr 27, 2026 | 9.3 | 37 | NO | NO |
CVE-2026-7161CRITICAL An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to crede | May 4, 2026 | 9.3 | 35 | NO | NO |
CVE-2024-12297CRITICAL Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are inv | Jan 15, 2025 | 9.2 | 29 | NO | NO |
CVE-2020-10284CRITICAL No authentication is required to control the robot inside the network, moreso the latest available user manual shows an option that lets the user to add a password to the robot but | Jul 15, 2020 | 9.1 | 29 | NO | NO |
CVE-2025-59093HIGH Exos 9300 instances are using a randomly generated database password to connect to the configured MSSQL server. The password is derived from static random values, which are concate | Jan 26, 2026 | 8.5 | 27 | NO | NO |
CVE-2020-10286HIGH the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted acc | Jul 15, 2020 | 8.8 | 27 | NO | NO |
CVE-2024-9138HIGH Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded creden | Jan 3, 2025 | 7.2 | 25 | NO | NO |
CVE-2025-7020MEDIUM An incorrect encryption implementation vulnerability exists in the system log dump feature of BYD's DiLink 3.0 OS (e.g. in the model ATTO3). An attacker with physical access to the | Aug 9, 2025 | 5.1 | 20 | NO | NO |
CVE-2024-5244MEDIUM TP-Link Omada ER605 Reliance on Security Through Obscurity Vulnerability. This vulnerability allows network-adjacent attackers to access or spoof DDNS messages on affected installa | May 23, 2024 | 4.2 | 17 | NO | NO |
CVE-2020-10277MEDIUM There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalati | Jun 24, 2020 | 6.4 | 17 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.