CWE-521: Weak Password Requirements
The product does not require that users should have strong passwords.
121 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-12364 — Weak Password Policy
- CVE-2026-25715 — Jinan USR IOT Technology Limited (PUSR) USR-W610 Weak Password Requirements
- CVE-2025-25211 — Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited,
- CVE-2025-55299 — VaulTLS has a password-based login exploit in additional user accounts
- CVE-2024-48845 — Weak Password Rules/Strength
- CVE-2026-27575 — Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change
- CVE-2025-55034 — General Industrial Controls Lynx+ Gateway Weak Password Requirements
- CVE-2025-9964 — Weak Authentication for Root User
- CVE-2025-23408 — Apache Fineract: weak password policy
- CVE-2025-11200 — MLflow Weak Password Requirements Authentication Bypass Vulnerability
- CVE-2026-85216 — MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials
- CVE-2026-6284 — Horner Automation Cscape and XL4, XL7 PLC Weak password requirements
- CVE-2026-33771 — CTP OS: Configuring password requirements does not work which permits the use of weak passwords
- CVE-2026-19293 — SMP security request
- CVE-2025-34058 — Hikvision Streaming Media Management Server Default Credentials and Authenticated Arbitrary File Read
- CVE-2026-12504 — Loytec LINX firmware: Improper Authentication in PAM configuration
- CVE-2025-67513 — FreePBX Endpoint Manager's Weak Default Password Allows Unauthenticated Access in Endpoint Module REST API
- CVE-2025-12552 — Insufficient Password Policy
- CVE-2024-41683 — A vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not prop
- CVE-2024-1346 — Weak MySQL database root password in LaborOfficeFree
Recently published
- CVE-2026-85216 — MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials
- CVE-2026-19293 — SMP security request
- CVE-2026-12504 — Loytec LINX firmware: Improper Authentication in PAM configuration
- CVE-2026-56577 — HCL MyCloud affected by Weak Password Policy
- CVE-2026-35097 — Weak Password Requirements in KTM System e-BOK
- CVE-2026-11493 — Tenda AC15 Samba smb.conf weak password
- CVE-2024-40684 — IBM Operations Analytics - Log Analysis is affected by Weak Password Policy and Inadequate Account Lockout Mechanism
- CVE-2026-9394 — Besen BS20 EV Charging Station Bluetooth Low Energy weak password
- CVE-2026-41038 — Weak Password Policy Vulnerability in Quantum Networks Router QN-I-470
- CVE-2026-6284 — Horner Automation Cscape and XL4, XL7 PLC Weak password requirements
- CVE-2026-33771 — CTP OS: Configuring password requirements does not work which permits the use of weak passwords
- CVE-2026-34203 — Nautobot: Management of users via REST API does not apply configured password validators
- CVE-2025-55269 — HCL Aftermarket DPC is affected by Weak Password Policy vulnerability
- CVE-2026-27575 — Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change
- CVE-2026-25715 — Jinan USR IOT Technology Limited (PUSR) USR-W610 Weak Password Requirements
- CVE-2026-1408 — Beetel 777VR1 UART weak password
- CVE-2025-55252 — HCL AION is affected by a Weak Password Policy vulnerability
- CVE-2025-68963 — Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may af
- CVE-2025-23408 — Apache Fineract: weak password policy
- CVE-2025-67513 — FreePBX Endpoint Manager's Weak Default Password Allows Unauthenticated Access in Endpoint Module REST API