CWE-255: CWE-255

11
Total CVEs
0
Critical
5
High
6.2
Avg CVSS

Yearly Trend

2025
8
2021
3

Top Affected Vendors

1 Intelbras 1
2 Dell 1
3 Furbo 1
4 Parallels 1
5 Arista 1

All CWE-255 CVEs (11)

CVE-2021-28498
8.7

Arista MOS software stores user enable passwords in clear text, allowing unprivileged users to gain complete system access. This affects Arista 7130 p...

Sep 9, 2021
CVE-2021-21505
8.0

CVE-2021-21505 is a critical vulnerability in Dell EMC Integrated System for Microsoft Azure Stack Hub where an undocumented default iDRAC account exi...

May 6, 2021
CVE-2025-11284
7.3

This vulnerability in Zytec Dalian Zhuoyun Technology Central Authentication Service 3 allows attackers to bypass authentication using hard-coded cred...

Oct 5, 2025
CVE-2020-8968
7.1

CVE-2020-8968 allows a local attacker to retrieve Parallels RAS profile passwords in clear text by uploading a previously stored encrypted file. This ...

Dec 17, 2021
CVE-2025-11649
7.0

This vulnerability allows attackers with local access to exploit a hard-coded password in the Root Account Handler component of Tomofun Furbo pet came...

Oct 12, 2025
CVE-2025-11666
6.7

This vulnerability in Tenda RP3 Pro routers allows local attackers to exploit a hard-coded password in the firmware update mechanism. Attackers with p...

Oct 13, 2025
CVE-2025-15128
5.3

This vulnerability in ZKTeco BioTime allows attackers to remotely access and manipulate credential storage parameters, leading to unprotected storage ...

Dec 28, 2025
CVE-2025-13221
5.3

This vulnerability in Intelbras UnniTI 24.07.11 allows remote attackers to access plaintext admin credentials stored in the /xml/sistema/usuarios.xml ...

Nov 15, 2025
CVE-2025-13187
5.3

This vulnerability in Intelbras ICIP 2.0.20 allows remote attackers to access plaintext admin credentials stored in the /xml/sistema/acessodeusuario.x...

Nov 14, 2025
CVE-2025-14183
4.3

This vulnerability in SGAI Space1 NAS devices allows remote attackers to retrieve stored credentials via unprotected API endpoints. It affects users o...

Dec 7, 2025
CVE-2025-15151
3.7

This vulnerability in TaleLin Lin-CMS allows attackers to manipulate username/password arguments in test configuration files, potentially exposing cre...

Dec 28, 2025

About CWE-255 (CWE-255)

Our database tracks 11 CVEs classified as CWE-255, with 0 rated critical and 5 rated high severity. The average CVSS score for CWE-255 vulnerabilities is 6.2.

External reference: View CWE-255 on MITRE CWE →

Monitor CWE-255 Vulnerabilities

Get alerted when new CWE-255 CVEs affect your infrastructure.

Start Monitoring Free