Weaknesses of type CWE-521
159 resultsRequisitos frágeis de senha
A aplicação aceita senhas muito fracas — curtas, sem complexidade, previsíveis — permitindo que atacantes quebrem credenciais por força bruta ou adivinhação. Isso compromete toda a cadeia de autenticação, independentemente de outros controles de segurança.
Example
Um banco digital permite cadastrar senhas com 3 caracteres e sem exigir letras, números ou símbolos. Um atacante consegue comprometer contas massivamente usando dicionários simples ou força bruta rápida.
How to mitigate
Implemente política obrigatória: mínimo 12 caracteres, mistura de maiúsculas, minúsculas, números e símbolos. Rejeite senhas baseadas em dicionários comuns e implemente limite de tentativas falhadas com lockout temporário.
CVE-2025-68716HIGHKAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configuEPSS 0.2%CVE-2025-46742MEDIUMImproper Access ControlEPSS 0.2%CVE-2026-11493LOWTenda AC15 Samba smb.conf weak passwordEPSS 0.2%CVE-2025-55299CRITICALVaulTLS has a password-based login exploit in additional user accountsEPSS 0.2%CVE-2025-9964HIGHWeak Authentication for Root UserEPSS 0.2%CVE-2023-50305MEDIUMIBM Engineering Requirements Management information disclosureEPSS 0.2%CVE-2026-9394LOWBesen BS20 EV Charging Station Bluetooth Low Energy weak passwordEPSS 0.2%CVE-2025-55252LOWHCL AION is affected by a Weak Password Policy vulnerabilityEPSS 0.2%CVE-2023-24502HIGH Electra Central AC unit – Easily calculated passwordEPSS 0.2%CVE-2026-41038HIGHWeak Password Policy Vulnerability in Quantum Networks Router QN-I-470EPSS 0.2%CVE-2026-56577LOWHCL MyCloud affected by Weak Password PolicyEPSS 0.2%CVE-2024-1345MEDIUMWeak MySQL database root password in LaborOfficeFreeEPSS 0.2%CVE-2026-19293HIGHSMP security requestEPSS 0.1%CVE-2026-12504HIGHLoytec LINX firmware: Improper Authentication in PAM configurationEPSS 0.1%CVE-2025-68963MEDIUMMan-in-the-middle attack vulnerability in the Clone module.
Impact: Successful exploitation of this vulnerability may affect service confideEPSS 0.1%CVE-2025-1993MEDIUMIBM App Connect Enterprise Certified Container information disclosureEPSS 0.1%CVE-2024-0676MEDIUMWeak password requirement vulnerability in Lamassu Bitcoin ATM Douro machinesEPSS 0.1%CVE-2024-45374MEDIUMgoTenna Pro ATAK Plugin Weak Password RequirementsEPSS 0.1%CVE-2024-47121MEDIUMWeak Passwords Requirements in goTenna ProEPSS 0.1%