CWE-940: CWE-940
Yearly Trend
Top Affected Vendors
All CWE-940 CVEs (15)
CVE-2025-61932 is a critical vulnerability in Lanscope Endpoint Manager (On-Premises) that allows unauthenticated remote attackers to execute arbitrar...
Oct 20, 2025This vulnerability allows remote attackers to perform traffic injection attacks against Caterease software due to improper verification of communicati...
Aug 2, 2024This critical vulnerability in Tenda AX2pro routers allows remote attackers to execute arbitrary code through the routing functionality. Attackers can...
Jul 16, 2024This vulnerability in Chunghwa Telecom NOKIA G-040W-Q routers allows unauthenticated remote attackers to send crafted ICMP redirect messages to manipu...
Nov 3, 2023A remote code execution vulnerability in H3C Magic RC3000 routers allows attackers to execute arbitrary code via the routing functionality. This affec...
Jul 16, 2024This vulnerability allows unprivileged local users to access D-Bus services as root through the Deepin dde-api-proxy service, which runs with root pri...
Jan 24, 2025This vulnerability allows unauthenticated remote attackers to interfere with TCP connection setup by exploiting improper sequence number validation, p...
Dec 9, 2025This vulnerability in OpenVPN allows attackers to hijack VPN sessions by spoofing source IP addresses, causing denial of service for legitimate client...
Dec 3, 2025This vulnerability affects Siemens SIMATIC CP 343-1 and SIPLUS NET CP 343-1 communication processors. An unauthenticated remote attacker can cause den...
Feb 13, 2024CVE-2025-25305 is a man-in-the-middle vulnerability in Home Assistant Core caused by improper SSL certificate verification. When integrations migrated...
Feb 18, 2025This vulnerability allows attackers on the same wireless network to disrupt or hijack TCP connections by sending forged TCP RST packets to the router....
Jun 17, 2024This vulnerability allows attackers to spoof and route arbitrary network traffic through systems with IPv4-in-IPv6 or IPv6-in-IPv6 tunneling enabled, ...
Jan 14, 2025This vulnerability allows attackers on the same wireless network to disrupt or hijack TCP connections by sending forged TCP RST packets to the Redmi r...
Jun 17, 2024Dell PowerProtect Data Manager versions before 19.22 have a REST API vulnerability where improper verification of communication channels allows high-p...
Feb 19, 2026An unauthenticated attacker on the same wireless network can send crafted IPv6 Router Advertisement packets to temporarily change the IPv6 gateway on ...
Sep 24, 2025About CWE-940 (CWE-940)
Our database tracks 15 CVEs classified as CWE-940, with 4 rated critical and 6 rated high severity. The average CVSS score for CWE-940 vulnerabilities is 7.5.
External reference: View CWE-940 on MITRE CWE →
Monitor CWE-940 Vulnerabilities
Get alerted when new CWE-940 CVEs affect your infrastructure.
Start Monitoring Free