CVE-2026-49000
An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakage or tampering, such as hard-coded keys or the use of weak encryption algorithms.
Scoring
- Severity
- HIGH
- CVSS base score
- 7
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
- EPSS probability
- 0.12%
- CWE
- CWE-310
- Published
- 2026-05-27
- Last modified
- 2026-05-28
Affected products
- ZTE ZXUniPOS NDS-LTE
- ZTE ZXUniPOS NDS-LTE
- ZTE ZXUniPOS NDS-LTE
Weakness type
Related vulnerabilities
- CVE-2026-86280 — SourceCodester Syllabus-Aligned Learning Management & Examination System cict_portal.sql cleartext storage
- CVE-2026-82699 — sambitraj Student Management System Password aca.sql cleartext storage
- CVE-2026-82555 — TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values
- CVE-2026-81836 — RooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmission
- CVE-2026-77151 — lin-snow Ech0 crypto.go MD5Encrypt risky encryption
- CVE-2026-19896 — mangroup dtale Flask Session Cookie app.py build_secret_key random values
- CVE-2026-19891 — TRENDnet TEW-WLC100 IKE Phase 1 Aggressive Mode racoon.conf missing encryption
- CVE-2026-17616 — Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access