CWE-656 · 10 records
Reliance on Security Through Obscurity
CVEs in this class
10 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2026-7161No exploit | GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerabilitygeovision · gv-ip device utility · CWE-656 | Critical9.3 | — | 0.4% | May 3, 2026 |
37Monitor | CVE-2026-42363No exploit | GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerabilitygeovision inc. · gv-ip device utility · CWE-656 | Critical9.3 | — | 0.3% | Apr 26, 2026 |
36Monitor | CVE-2020-10284No exploit | RVD#3321: No Authentication required to exert manual control of the robotufactory · xarm studio · CWE-656 | Critical9.1 | — | 1.4% | Jul 15, 2020 |
36Monitor | CVE-2024-12297No exploit | Frontend Authorization Logic Disclosure Vulnerabilitymoxa · eds-508a series · CWE-656 | Critical9.2 | — | 0.8% | Jan 15, 2025 |
35Monitor | CVE-2020-10286No exploit | RVD#3323: Mismanaged permission implementation leads to privilege escalation, exfiltration of sensitive information, and DoSufactory · xarm 5 lite firmware · CWE-656 | High8.8 | — | 0.7% | Jul 15, 2020 |
34Monitor | CVE-2024-9138No exploit | Privilege Escalation in Cellular Router, Secure Router, and Network Security Appliancesmoxa · edr-810 series · CWE-656 | High8.6 | — | 1.2% | Jan 3, 2025 |
34Monitor | CVE-2025-59093No exploit | Insecure Password Derivation Function for Database Administrator in dormakaba Kaba exos 9300dormakaba · kaba exos 9300 · CWE-656 | High8.5 | — | 0.2% | Jan 26, 2026 |
25Monitor | CVE-2020-10277No exploit | RVD#2562: Booting from a live image leads to exfiltration of sensible information and privilege escalationmobile-industrial-robots · mir100 firmware · CWE-656 | Medium6.4 | — | 0.4% | Jun 24, 2020 |
20Monitor | CVE-2025-7020No exploit | BYD DiLink OS Incorrect encryption Implementation of system log dumpsbyd · dilink os · CWE-656 | Medium5.1 | — | 0.1% | Aug 9, 2025 |
16Monitor | CVE-2024-5244No exploit | TP-Link Omada ER605 Reliance on Security Through Obscurity Vulnerabilitytp-link · omada er605 firmware · CWE-656 | Medium4.2 | — | 0.4% | May 23, 2024 |
- CVE-2026-716137Monitor
GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerability
CriticalCVSS 9.3No exploitEPSS 0%geovision · gv-ip device utilityMay 3, 2026
- CVE-2026-4236337Monitor
GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerability
CriticalCVSS 9.3No exploitEPSS 0%geovision inc. · gv-ip device utilityApr 26, 2026
- CVE-2020-1028436Monitor
RVD#3321: No Authentication required to exert manual control of the robot
CriticalCVSS 9.1No exploitEPSS 1%ufactory · xarm studioJul 15, 2020
- CVE-2024-1229736Monitor
Frontend Authorization Logic Disclosure Vulnerability
CriticalCVSS 9.2No exploitEPSS 1%moxa · eds-508a seriesJan 15, 2025
- CVE-2020-1028635Monitor
RVD#3323: Mismanaged permission implementation leads to privilege escalation, exfiltration of sensitive information, and DoS
HighCVSS 8.8No exploitEPSS 1%ufactory · xarm 5 lite firmwareJul 15, 2020
- CVE-2024-913834Monitor
Privilege Escalation in Cellular Router, Secure Router, and Network Security Appliances
HighCVSS 8.6No exploitEPSS 1%moxa · edr-810 seriesJan 3, 2025
- CVE-2025-5909334Monitor
Insecure Password Derivation Function for Database Administrator in dormakaba Kaba exos 9300
HighCVSS 8.5No exploitEPSS 0%dormakaba · kaba exos 9300Jan 26, 2026
- CVE-2020-1027725Monitor
RVD#2562: Booting from a live image leads to exfiltration of sensible information and privilege escalation
MediumCVSS 6.4No exploitEPSS 0%mobile-industrial-robots · mir100 firmwareJun 24, 2020
- CVE-2025-702020Monitor
BYD DiLink OS Incorrect encryption Implementation of system log dumps
MediumCVSS 5.1No exploitEPSS 0%byd · dilink osAug 9, 2025
- CVE-2024-524416Monitor
TP-Link Omada ER605 Reliance on Security Through Obscurity Vulnerability
MediumCVSS 4.2No exploitEPSS 0%tp-link · omada er605 firmwareMay 23, 2024