Weaknesses of type CWE-640

219 results

Mecanismo fraco de recuperação de senha

É quando o sistema oferece um fluxo para recuperar senhas perdidas, mas esse fluxo usa verificações insuficientes (perguntas fáceis de responder, tokens previsíveis, links sem expiração) ou permite múltiplas tentativas sem limite. Um atacante consegue contornar a autenticação e assumir a conta sem saber a senha original.

Example

Um site que envia um e-mail com link de reset contendo um ID sequencial (user_id=1001, user_id=1002...), sem expiração, ou que valida a recuperação apenas pedindo a 'data de nascimento' — dados frequentemente públicos em redes sociais.

How to mitigate

Use tokens criptograficamente seguros e aleatórios com expiração curta (15-30 min). Implemente rate limiting rigoroso no fluxo de recuperação, valide o link apenas uma vez e considere autenticação multi-fator (SMS, app authenticator) como segunda camada de confirmação.

CVE-2023-4448MEDIUMOpenRapid RapidCMS run-movepass.php password recoveryEPSS 0.7%CVE-2026-25858CRITICALmacrozheng mall <= 1.0.3 Unauthenticated Password Reset via OTP DisclosureEPSS 0.6%CVE-2025-10127HIGHDaikin Europe N.V Security Gateway Weak Password Recovery Mechanism for Forgotten PasswordEPSS 0.6%CVE-2023-7264HIGHBuild App Online <= 1.0.22 - Account Takeover via Weak Password Reset MechanismEPSS 0.6%CVE-2022-47697CRITICALCOMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Account takeovEPSS 0.6%CVE-2026-11551CRITICALBranda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account TakeoverEPSS 0.6%CVE-2023-35717HIGHTP-Link Tapo C210 Password Recovery Authentication Bypass VulnerabilityEPSS 0.6%CVE-2024-9302HIGHApp Builder – Create Native Android & iOS Apps On The Flight <= 5.3.7 - Privilege Escalation and Account Takeover via Weak OTPEPSS 0.6%CVE-2026-15689CRITICALDancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_sendEPSS 0.6%CVE-2024-0186LOWHuiRan Host Reseller System HTTP POST Request password recoveryEPSS 0.6%CVE-2021-27654HIGHForgotten password reset functionality for local accounts can be used to bypass local authentication checks.EPSS 0.6%CVE-2023-47107HIGHPILOS account takeover through password reset poisoningEPSS 0.6%CVE-2024-2463HIGHWeak password recovery mechanism in CDeXEPSS 0.6%CVE-2024-0491MEDIUMHuaxia ERP UserController.java password recoveryEPSS 0.6%CVE-2026-7459HIGHSimple History – Track, Log, and Audit WordPress Changes <= 5.26.0 - Authenticated (Subscriber+) Account Takeover via Missing Authorization on Event Reaction EndpointEPSS 0.6%CVE-2015-10071LOWgitter-badger ezpublish-modern-legacy forgotpassword.php password recoveryEPSS 0.6%CVE-2025-64113CRITICALEmby Server allows attackers to gain administrative server access without preconditionsEPSS 0.6%CVE-2026-1325MEDIUMSangfor Operation and Maintenance Security Management System edit_pwd_mall password recoveryEPSS 0.6%CVE-2026-56081CRITICALCap-go - Account Lockout via 2FA Misconfiguration on Unverified EmailEPSS 0.6%CVE-2026-77264CRITICALAutomation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token DisclosureEPSS 0.6%