The web management interface of the device allows the administrator username and password to be set to blank values. On
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to
An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to syst
This vulnerability exists in Quantum Networks router due to lack of enforcement of strong password policies in the web-b
SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The roo
A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,
Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may af
A weakness has been identified in Tenda AC15 15.03.05.19. The impacted element is an unknown function of the file /etc_r
HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak
HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable pas
A vulnerability was determined in Besen BS20 EV Charging Station up to 20260426. This impacts an unknown function of the
HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force o
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creatio
A weakness has been identified in Beetel 777VR1 up to 01.00.09/01.00.09_55. This vulnerability affects unknown code of t
KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any alphabetic,
Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-
Frequently Asked Questions
What is CWE-521?
CWE-521 (CWE-521) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-521?
There are 20 CVE records associated with CWE-521 in our database. Of these, 3 are critical severity, 4 are high severity, and 4 are medium severity.
How can I protect against CWE-521 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-521 using AI-powered security agents.
Detect CWE-521 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-521 vulnerabilities across your infrastructure.
Get Started