CWE-258
CVEs classified under CWE-258, newest first.
2 CVEsRSS
CVE-2026-84398High· 7.5CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service
CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user…
▾ TwilightCareCam · HMT.CM2507 FirmwareEPSS 0.24%via NVD
CVE-2025-15679High· 7.3Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.
Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.
▾ TwilightBull · BullSequana XH3406EPSS 0.11%via NVD