General Bytes Crypto Application Server (CAS) beginning with version 20201208 prior to 20220531.38 (backport) and 202207
GALAYOU G2 cameras stream video output via RTSP streams. By default these streams are protected by randomly generated cr
The attacker may obtain root access by connecting to the UART port and this vulnerability requires the attacker to have
Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0
A potential security vulnerability has been identified in HP Sure Start’s protection of the Intel Flash Descriptor in ce
Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated
microCLAUDIA in v3.2.0 and prior has an improper access control vulnerability. This flaw allows an authenticated user t
Seeyon Zhiyuan OA Web Application System versions up to and including 7.0 SP1 improperly decode and parse the `enc` para
Anheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request fo
The Survision LPR Camera system does not enforce password protection by default. This allows access to the configuration
Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulne
PLANEX CS-QP50F-ING2 smart cameras expose a configuration backup interface over HTTP that does not require authenticatio
Denver SHO-110 IP cameras expose a secondary HTTP service on TCP port 8001 that provides access to a '/snapshot' endpoin
Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) versions
A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact
SiRcom SMART Alert (SiSA) allows unauthorized access to backend APIs. This allows an unauthenticated attacker to bypass
Dongyoung Media DM-AP240T/W wireless access points contain an unauthenticated configuration disclosure vulnerability in
Tellion HN-2204AP routers contain an unauthenticated configuration disclosure vulnerability in the /cgi-bin/system_confi
ESCAM QD-900 WIFI HD cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/hi351
Astak CM-818T3 2.4GHz wireless security surveillance cameras contain an unauthenticated configuration disclosure vulnera
ACE SECURITY WIP-90113 HD cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/
The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authenticatio
The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The serv
AirKeyboard iOS App 1.0.5 contains a missing authentication vulnerability that allows unauthenticated attackers to type
Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to
COMMAX Smart Home System allows an unauthenticated attacker to change configuration and cause denial-of-service through
COMMAX Smart Home System is a smart IoT home solution that allows an unauthenticated attacker to disclose RTSP credentia
Siklu MultiHaul TG series devices before version 2.0.0 contain an unauthenticated vulnerability that allows remote attac
In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of authentication in the configuration cha
WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) is vulnerable to Broken Access Control in initial configu
The MachineSense application programmable interface (API) is improperly protected and can be accessed without authe
RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior
u-boot bug that allows for u-boot shell and interrupt over UART
MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function
An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited all
A vulnerability allows unauthorized access to functionality inadequately constrained by ACLs. Attackers may exploit this
An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In t
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An a
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to
Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistak
A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited,
D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator
The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order
ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated u
Webhood is a self-hosted URL scanner used analyzing phishing and malicious sites. Webhood's backend container images in
An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET c
The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset
Frequently Asked Questions
What is CWE-306?
CWE-306 (CWE-306) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-306?
There are 3,424 CVE records associated with CWE-306 in our database. Of these, 1075 are critical severity, 1154 are high severity, and 604 are medium severity.
How can I protect against CWE-306 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-306 using AI-powered security agents.
Detect CWE-306 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-306 vulnerabilities across your infrastructure.
Get Started