CWE-337: PRNG
A Pseudo-Random Number Generator (PRNG) is initialized from a predictable seed, such as the process ID or system time.
13 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-7770 — Predictable Seed in Pseudo-Random Number Generator (PRNG) in Tigo Energy Cloud Connect Advanced
- CVE-2025-55069 — AutomationDirect CLICK PLUS Predictable Seed in Pseudo-Random Number Generator
- CVE-2026-25235 — PEAR Has a Predictable Verification Hash in Election Account Requests
- CVE-2026-26018 — CoreDNS Loop Detection Denial of Service Vulnerability
- CVE-2025-62710 — Sakai kernel-impl: predictable PRNG used to generate server‑side encryption key in EncryptionUtilityServiceImpl
- CVE-2025-20613 — Predictable Seed in Pseudo-Random Number Generator (PRNG) in the firmware for some Intel(R) TDX may allow an authenticat
- CVE-2024-22194 — cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code
Recently published
- CVE-2026-26018 — CoreDNS Loop Detection Denial of Service Vulnerability
- CVE-2026-25235 — PEAR Has a Predictable Verification Hash in Election Account Requests
- CVE-2025-62710 — Sakai kernel-impl: predictable PRNG used to generate server‑side encryption key in EncryptionUtilityServiceImpl
- CVE-2025-55069 — AutomationDirect CLICK PLUS Predictable Seed in Pseudo-Random Number Generator
- CVE-2025-20613 — Predictable Seed in Pseudo-Random Number Generator (PRNG) in the firmware for some Intel(R) TDX may allow an authenticat
- CVE-2025-7770 — Predictable Seed in Pseudo-Random Number Generator (PRNG) in Tigo Energy Cloud Connect Advanced
- CVE-2024-22194 — cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code