CWE-261: Weak Encoding for Password
Obscuring a password with a trivial encoding does not protect the password.
40 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-11500 — Credentials exposure in tinycontrol devices
- CVE-2024-0556 — Weak Cryptography for Passwords vulnerability on WIC1200
- CVE-2026-22543 — WEEK ENCODING FOR PASSWORDS
- CVE-2025-2862 — Weak Encoding for Password vulnerability in saTECH BCU
- CVE-2024-5434 — Weak Encoding for Password vulnerability in Campbell Scientific CSI Web Server and RTMC
- CVE-2024-34542 — Advantech ADAM-5630 Weak Encoding for Password
- CVE-2025-11155 — WEAK ENCODING FOR PASSWORD IN DEVICE SERVER CONFIGURATION
- CVE-2024-37187 — Advantech ADAM-5550 Weak Encoding for Password
- CVE-2025-26401 — Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authen
- CVE-2026-0809 — Weak KSeF token encoding in Streamsoft Prestiż
- CVE-2025-25298 — Missing Maximum Password Length Validation in Strapi Password Hashing
- CVE-2024-52334 — A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not
- CVE-2025-67652 — AutomationDirect CLICK Programmable Logic Controller Weak Encoding for Password
- CVE-2026-63424 — During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could all
- CVE-2026-67596 — CSL 1010 M2M 3G WiFi Module 2.2.1.4 Weak Encryption via Router.cfg
- CVE-2024-23492 — Commend WS203VICM Weak Encoding for Password
- CVE-2024-34113 — ColdFusion | Weak Cryptography for Passwords (CWE-261)
- CVE-2026-53692 — Weak hashing algorithm in Redeight CMS
- CVE-2026-40639 — Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical
- CVE-2026-25607 — Weak password encoding in STER
Recently published
- CVE-2026-63424 — During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could all
- CVE-2026-67596 — CSL 1010 M2M 3G WiFi Module 2.2.1.4 Weak Encryption via Router.cfg
- CVE-2026-53692 — Weak hashing algorithm in Redeight CMS
- CVE-2026-40639 — Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical
- CVE-2026-25607 — Weak password encoding in STER
- CVE-2025-11500 — Credentials exposure in tinycontrol devices
- CVE-2026-0809 — Weak KSeF token encoding in Streamsoft Prestiż
- CVE-2024-52334 — A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not
- CVE-2025-67652 — AutomationDirect CLICK Programmable Logic Controller Weak Encoding for Password
- CVE-2026-22543 — WEEK ENCODING FOR PASSWORDS
- CVE-2025-25298 — Missing Maximum Password Length Validation in Strapi Password Hashing
- CVE-2025-11155 — WEAK ENCODING FOR PASSWORD IN DEVICE SERVER CONFIGURATION
- CVE-2025-26401 — Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authen
- CVE-2025-2862 — Weak Encoding for Password vulnerability in saTECH BCU
- CVE-2024-34542 — Advantech ADAM-5630 Weak Encoding for Password
- CVE-2024-37187 — Advantech ADAM-5550 Weak Encoding for Password
- CVE-2024-34113 — ColdFusion | Weak Cryptography for Passwords (CWE-261)
- CVE-2024-5434 — Weak Encoding for Password vulnerability in Campbell Scientific CSI Web Server and RTMC
- CVE-2024-23492 — Commend WS203VICM Weak Encoding for Password
- CVE-2024-0556 — Weak Cryptography for Passwords vulnerability on WIC1200