CVE-2025-36754None▾ SunlitThe authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
The authentication mechanism on web interface is not properly implemented. It is possible to bypass authentication checks by crafting a post request with new settings since there is no session token or authentication in place. This would allow an attacker for instance to point the device to an arbitrary address for domain name resolution to e.g. facililitate a man-in-the-middle (MitM) attack.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-59385Critical· 9.8An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-36753Critical· 9.8The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default, allowing an attacker to attain debug access to the device and to extracting secrets or domains from within the device
CVE-2026-33586Medium· 6.3Authenticated users are able to manipulate both the SMTP envelope “Envelope-from” and “From” fields when sending emails through OVH mail servers. Due to OVH's default SPF configuration, which commonly includes include:mx.ovh.com, any …
GHSA-4mp6-8448-9vgvMedium· 7.3Duplicate Advisory: PraisonAI: AgentMail webhook lacks signature verification, allowing unauthenticated message injection and sender spoofing
CVE-2026-97146Medium· 4.8Apache YuniKorn 1.9.0 and earlier allows bypassing the check for the user annotation by setting a secondary label on the pod. If the pod has the label 'app=yunikorn' the checks limiting the user annotation content are not run
CVE-2021-47923Critical· 9.8OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie