CWE-294

High likelihood

Authentication Bypass by Capture-replay

Parent: CWE-1390 - Weak Authentication

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

210 vulnerabilities with CWE-294
CVE-2026-41351 MEDIUM
OpenClaw < 2026.3.31 - Webhook Replay Detection Bypass via Base64 Signature Re-encoding
CVSS 5.3
CVE-2026-35618 MEDIUM
OpenClaw < 2026.3.23 - Replay Identity Drift via Query-Only Variants in Plivo V2 Verification
CVSS 6.5
CVE-2026-30080 HIGH
OpenAirInterface 2.2.0 - Auth Bypass
CVSS 7.5
CVE-2026-34209 HIGH
mppx: Tempo has a session close voucher bypass vulnerability due to settled amount equality
CVSS 7.5
CVE-2026-32987 CRITICAL
OpenClaw < 2026.3.13 - Bootstrap Setup Code Replay via Device Pairing
CVSS 9.8
CVE-2026-27855 MEDIUM
OX Dovecot Pro <2.3.0 - Replay Attack
CVSS 6.8
CVE-2026-4583 MEDIUM
Shenzhen HCC Technology MPOS M6 PLUS Bluetooth authentication replay
CVSS 5.0
CVE-2026-32053 MEDIUM
OpenClaw < 2026.2.23 - Twilio Webhook Replay Bypass via Randomized Event ID Normalization
CVSS 6.5
CVE-2026-28449 MEDIUM
OpenClaw < 2026.2.25 - Webhook Replay Attack via Missing Durable Replay Suppression
CVSS 6.5
CVE-2026-20999 HIGH
Samsung Mobile Smart Switch - Authentication Bypass
CVSS 7.5
CVE-2026-28787 HIGH
OneUptime <=10.0.11 - Auth Bypass
CVSS 8.2
CVE-2026-30789 CRITICAL
RustDesk Client <1.4.5 - Auth Bypass
CVSS 9.8
CVE-2026-2540 HIGH
Micca KE700 - Replay Attack
CVE-2026-24027 MEDIUM
Crafted Zones - DoS
CVSS 5.3
CVE-2026-1743 LOW
DJI Mavic Mini, Air, Spark and Mini SE <01.00.0500 - Auth Bypass
CVSS 3.1
CVE-2025-13777 HIGH
ABB AWIN GW100 rev.2 & GW120 - Auth Bypass
CVSS 8.3
CVE-2025-67135 CRITICAL
PF-50 1.2 - Code Injection
CVSS 9.8
CVE-2025-59023 HIGH
Recursor - DoS
CVSS 8.2
CVE-2025-69822 HIGH
Atomberg Erica Smart Fan Firmware - Information Disclosure
CVSS 7.4
CVE-2025-68671 MEDIUM
LakeFS <1.75.0 - Replay Attack
CVSS 6.5
CVE-2025-65553 MEDIUM
D3D Wi-Fi Home Security System ZX-G12 v2.1.17 - DoS
CVSS 6.5
CVE-2025-65552 CRITICAL
D3D Wi-Fi Home Security System ZX-G12 v2.1.1 - Info Disclosure
CVSS 9.8
CVE-2025-69197 MEDIUM
Pterodactyl <1.11.11 - Info Disclosure
CVSS 6.5
CVE-2025-40807 MEDIUM
Gridscale X Prepay <V4.2.1 - Auth Bypass
CVSS 6.3
CVE-2025-30201 HIGH
Wazuh <4.13.0 - Privilege Escalation
CVSS 7.7
Details
Vulnerabilities 210
Exploit Likelihood High