CWE-291: Reliance on IP Address for Authentication
The product uses an IP address for authentication.
10 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-4252 — Tenda AC8 IPv6 check_is_ipv6 ip address for authentication
- CVE-2024-23309 — The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due
- CVE-2025-59101 — Insufficient Session Management in dormakaba access manager
- CVE-2025-34202 — Vasion Print (formerly PrinterLogic) Insecure Access to Docker Instances WAN
- CVE-2025-66602 — A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts access
- CVE-2026-3690 — OpenClaw Canvas Authentication Bypass Vulnerability
- CVE-2024-32765 — QTS, QuTS hero
- CVE-2026-86485 — In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks
Recently published
- CVE-2026-86485 — In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks
- CVE-2026-3690 — OpenClaw Canvas Authentication Bypass Vulnerability
- CVE-2026-4252 — Tenda AC8 IPv6 check_is_ipv6 ip address for authentication
- CVE-2025-66602 — A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts access
- CVE-2025-59101 — Insufficient Session Management in dormakaba access manager
- CVE-2025-34202 — Vasion Print (formerly PrinterLogic) Insecure Access to Docker Instances WAN
- CVE-2024-23309 — The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due
- CVE-2024-32765 — QTS, QuTS hero