Vulnerabilities (CVE)

Filtered by CWE-306
Total 2862 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-27256 2026-06-17 N/A 8.3 HIGH
Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to a missing SSH server authentication. Since the client connection is not authenticated, an attacker may perform a man-in-the-middle attack on the network.
CVE-2025-27214 2026-06-17 N/A 9.8 CRITICAL
A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical or adjacent access to perform an unauthorized factory reset. Affected Products: UniFi Connect EV Station Pro (Version 1.5.18 and earlier) Mitigation: Update UniFi Connect EV Station Pro to Version 1.5.27 or later
CVE-2025-27020 1 Nokia 2 Infinera Mtc-9, Infinera Mtc-9 Firmware 2026-06-17 N/A 9.8 CRITICAL
Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system . This issue affects MTC-9: from R22.1.1.0275 before R23.0.
CVE-2025-27019 1 Nokia 2 Infinera Mtc-9, Infinera Mtc-9 Firmware 2026-06-17 N/A 9.8 CRITICAL
Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user accounts and obtain system access by activating a reverse shell.This issue affects MTC-9: from R22.1.1.0275 before R23.0.
CVE-2025-26468 1 Cyberdata 1 011209 Sip Emergency Intercom 2026-06-17 N/A 7.5 HIGH
CyberData  011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a denial-of-service condition or system disruption.
CVE-2025-26366 1 Q-free 1 Maxtime 2026-06-17 N/A 7.5 HIGH
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to disable front panel authentication via crafted HTTP requests.
CVE-2025-26365 1 Q-free 1 Maxtime 2026-06-17 N/A 7.5 HIGH
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable front panel authentication via crafted HTTP requests.
CVE-2025-26364 1 Q-free 1 Maxtime 2026-06-17 N/A 7.5 HIGH
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to disable an authentication profile server via crafted HTTP requests.
CVE-2025-26363 1 Q-free 1 Maxtime 2026-06-17 N/A 7.5 HIGH
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable an authentication profile server via crafted HTTP requests.
CVE-2025-26362 1 Q-free 1 Maxtime 2026-06-17 N/A 7.5 HIGH
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to set an arbitrary authentication profile server via crafted HTTP requests.
CVE-2025-26361 1 Q-free 1 Maxtime 2026-06-17 N/A 9.1 CRITICAL
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to factory reset the device via crafted HTTP requests.
CVE-2025-26360 1 Q-free 1 Maxtime 2026-06-17 N/A 5.3 MEDIUM
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/persistance/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to delete dashboards via crafted HTTP requests.
CVE-2025-26359 1 Q-free 1 Maxtime 2026-06-17 N/A 9.8 CRITICAL
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to reset user PINs via crafted HTTP requests.
CVE-2025-26347 1 Q-free 1 Maxtime 2026-06-17 N/A 9.8 CRITICAL
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to edit user permissions via crafted HTTP requests.
CVE-2025-26345 1 Q-free 1 Maxtime 2026-06-17 N/A 9.8 CRITICAL
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to edit user group permissions via crafted HTTP requests.
CVE-2025-26344 1 Q-free 1 Maxtime 2026-06-17 N/A 9.8 CRITICAL
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/guest-mode/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enable passwordless guest mode via crafted HTTP requests.
CVE-2025-26342 1 Q-free 1 Maxtime 2026-06-17 N/A 9.8 CRITICAL
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to create arbitrary users, including administrators, via crafted HTTP requests.
CVE-2025-26341 1 Q-free 1 Maxtime 2026-06-17 N/A 9.8 CRITICAL
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to reset arbitrary user passwords via crafted HTTP requests.
CVE-2025-26339 1 Q-free 1 Maxtime 2026-06-17 N/A 9.8 CRITICAL
A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to affect the device confidentiality, integrity, or availability in multiple unspecified ways via crafted HTTP requests.
CVE-2025-25736 1 Kapsch 4 Ris-9160, Ris-9160 Firmware, Ris-9260 and 1 more 2026-06-17 N/A 6.8 MEDIUM
Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android Debug Bridge (ADB) pre-installed (/mnt/c3platpersistent/opt/platform-tools/adb) and enabled by default, allowing unauthenticated root shell access to the cellular modem via the default 'kapsch' user.