CWE-291Variant

Reliance on IP Address for Authentication

Incomplete in the CWE catalog · 9 CVEs mapped

9
CVEs mapped
7.4
Median CVSS
What it is

The product uses an IP address for authentication.

Recent examples
7.4cvss
CVE-2026-3690

OpenClaw Canvas Authentication Bypass Vulnerability

OpenClaw Canvas Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of OpenClaw. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the the authentication function for canvas endpoints. The issue results from improper implementation of authentication. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-29311.

HIGHno explanation yet
1%
epss
9.3cvss
CVE-2026-4252

Tenda AC8 IPv6 check_is_ipv6 ip address for authentication

A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on ip address for authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

CRITICALno explanation yet
1%
epss
6.9cvss
CVE-2025-66602

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts access by IP address. When a worm that randomly searches for IP addresses intrudes into the network, it could potentially be attacked by the worm. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-291
Abstraction
Variant
Structure
Simple
Status
Incomplete
References (2)