Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-305 (使用基本弱点进行的认证绕过) — Vulnerability Class 130

130 vulnerabilities classified as CWE-305 (使用基本弱点进行的认证绕过). AI Chinese analysis included.

CWE-305 represents a critical authentication bypass vulnerability where the core cryptographic algorithm remains robust, yet the implementation allows attackers to circumvent security controls through a distinct, primary flaw. This weakness typically manifests when developers rely on flawed logic, such as trusting client-side validation or improperly handling session tokens, rather than strengthening the underlying cipher. Attackers exploit these implementation gaps by manipulating request parameters, bypassing access checks, or exploiting race conditions to gain unauthorized access without breaking the encryption itself. To prevent this, developers must ensure that authentication mechanisms are strictly server-side enforced, avoiding any trust in client-supplied data. Comprehensive input validation, rigorous session management, and regular security audits are essential to identify and remediate these secondary weaknesses, ensuring that the authentication process remains resilient against evasion techniques that target implementation errors rather than algorithmic strength.

MITRE CWE Description
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
Common Consequences (1)
Access ControlBypass Protection Mechanism
CVE IDTitleCVSSSeverityPublished
CVE-2024-12802 SonicWALL SSL-VPN 安全漏洞 — SonicOS 9.8 -2025-01-09
CVE-2023-46611 WordPress YOP Poll plugin <= 6.5.28 - Vote Manipulation Due to Broken Captcha Control Vulnerability — YOP Poll 5.3 Medium2025-01-02
CVE-2022-48470 编号已被CVE保留 — HarmonyOS AILife Solution 6.0 4.0 Medium2024-12-28
CVE-2024-12582 Skupper: skupper-cli: flawed authentication method may lead to arbitrary file read or denial of service 7.1 High2024-12-24
CVE-2021-26102 Avfirewalls FortiWAN 授权问题漏洞 — FortiWAN 9.8 Critical2024-12-19
CVE-2023-20154 Cisco Modeling Labs External Authentication Bypass Vulnerability — Cisco Modeling Labs 9.1 Critical2024-11-15
CVE-2024-10394 Theft of credentials in Unix client PAGs — OpenAFS 7.8AIHighAI2024-11-14
CVE-2024-10082 CodeChecker 安全漏洞 — CodeChecker 8.7 High2024-11-06
CVE-2024-50478 WordPress 1-Click Login: Passwordless Authentication plugin 1.4.5 - Broken Authentication vulnerability — 1-Click Login: Passwordless Authentication 9.8 Critical2024-10-28
CVE-2024-9683 Quay: quay allows successful authentication with trucated version of the password 4.8 Medium2024-10-17
CVE-2024-20463 Cisco ATA 190 Series Analog Telephone Adapter Firmware Command Injection and Denial of Service Vulnerability — Cisco Analog Telephone Adaptor (ATA) Software 5.4 Medium2024-10-16
CVE-2024-5957 Trellix IPS Manager 安全漏洞 — Intrusion Prevention System (IPS) Manager 6.3 Medium2024-09-05
CVE-2024-5956 Trellix IPS Manager 安全漏洞 — Intrusion Prevention System (IPS) Manager 6.5 Medium2024-09-05
CVE-2024-7557 Odh-dashboard: odh-model-controller: cross-model authentication bypass in openshift ai 8.8 High2024-08-08
CVE-2024-4784 Authentication Bypass by Primary Weakness in GitLab — GitLab 4.2 Medium2024-08-08
CVE-2024-6637 WooCommerce - Social Login <= 2.7.3 - Unauthenticated Privilege Escalation via One-Time Password — WooCommerce - Social Login 7.3 High2024-07-20
CVE-2024-38433 Nuvoton - CWE-305: Authentication Bypass by Primary Weakness — NPCM7xx (Poleg) BootBlock 6.7 Medium2024-07-11
CVE-2024-39899 PrivateBin allows shortening of URLs for other domains — PrivateBin 5.3 Medium2024-07-09
CVE-2023-41920 Authentication Bypass by Primary Weakness in Kiloview P1/P2 devices — P1/P2 9.8 Critical2024-07-02
CVE-2023-4727 Ca: token authentication bypass vulnerability 7.5 High2024-06-11
CVE-2024-36388 MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function — DeviceHub 10.0 Critical2024-06-02
CVE-2024-34077 MantisBT user account takeover in the signup/reset password process — mantisbt 7.3 High2024-05-13
CVE-2024-20378 Cisco IP Phone 安全漏洞 — Cisco IP Phones with Multiplatform Firmware 7.5 High2024-05-01
CVE-2023-6153 Authentication Bypass in TeoSOFT Software TeoBASE — TeoBASE 9.8 Critical2024-03-27
CVE-2024-1202 Authentication Bypass in XPodas' Octopod — Octopod 9.8 Critical2024-03-05
CVE-2023-7103 Authentication Bypass in ZKSoftware's UFace 5 — UFace 5 9.8 Critical2024-03-05
CVE-2024-1403 Authentication Bypass in OpenEdge Authentication Gateway and AdminServer — OpenEdge 10.0 Critical2024-02-27
CVE-2024-20674 Windows Kerberos Security Feature Bypass Vulnerability — Windows 10 Version 1809 8.8 High2024-01-09
CVE-2023-6998 Lockscreen bypass in eWeLink App — eWeLink - Smart Home 7.7 High2023-12-30
CVE-2023-4939 SALESmanago <= 3.2.4 - Log Injection via Weak Authentication Token — SALESmanago & Leadoo 5.3 Medium2023-10-21

Vulnerabilities classified as CWE-305 (使用基本弱点进行的认证绕过) represent 130 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.