CWE-294
High likelihoodAuthentication Bypass by Capture-replay
Parent: CWE-1390 - Weak Authentication
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
210 vulnerabilities with CWE-294
CVE-2026-41351
MEDIUM
OpenClaw < 2026.3.31 - Webhook Replay Detection Bypass via Base64 Signature Re-encoding
CVSS 5.3
CVE-2026-35618
MEDIUM
OpenClaw < 2026.3.23 - Replay Identity Drift via Query-Only Variants in Plivo V2 Verification
CVSS 6.5
CVE-2026-30080
HIGH
OpenAirInterface 2.2.0 - Auth Bypass
CVSS 7.5
CVE-2026-34209
HIGH
mppx: Tempo has a session close voucher bypass vulnerability due to settled amount equality
CVSS 7.5
CVE-2026-32987
CRITICAL
OpenClaw < 2026.3.13 - Bootstrap Setup Code Replay via Device Pairing
CVSS 9.8
CVE-2026-27855
MEDIUM
OX Dovecot Pro <2.3.0 - Replay Attack
CVSS 6.8
CVE-2026-4583
MEDIUM
Shenzhen HCC Technology MPOS M6 PLUS Bluetooth authentication replay
CVSS 5.0
CVE-2026-32053
MEDIUM
OpenClaw < 2026.2.23 - Twilio Webhook Replay Bypass via Randomized Event ID Normalization
CVSS 6.5
CVE-2026-28449
MEDIUM
OpenClaw < 2026.2.25 - Webhook Replay Attack via Missing Durable Replay Suppression
CVSS 6.5
CVE-2026-20999
HIGH
Samsung Mobile Smart Switch - Authentication Bypass
CVSS 7.5
CVE-2026-28787
HIGH
OneUptime <=10.0.11 - Auth Bypass
CVSS 8.2
CVE-2026-30789
CRITICAL
RustDesk Client <1.4.5 - Auth Bypass
CVSS 9.8
CVE-2026-2540
HIGH
Micca KE700 - Replay Attack
CVE-2026-24027
MEDIUM
Crafted Zones - DoS
CVSS 5.3
CVE-2026-1743
LOW
DJI Mavic Mini, Air, Spark and Mini SE <01.00.0500 - Auth Bypass
CVSS 3.1
CVE-2025-13777
HIGH
ABB AWIN GW100 rev.2 & GW120 - Auth Bypass
CVSS 8.3
CVE-2025-67135
CRITICAL
PF-50 1.2 - Code Injection
CVSS 9.8
CVE-2025-59023
HIGH
Recursor - DoS
CVSS 8.2
CVE-2025-69822
HIGH
Atomberg Erica Smart Fan Firmware - Information Disclosure
CVSS 7.4
CVE-2025-68671
MEDIUM
LakeFS <1.75.0 - Replay Attack
CVSS 6.5
CVE-2025-65553
MEDIUM
D3D Wi-Fi Home Security System ZX-G12 v2.1.17 - DoS
CVSS 6.5
CVE-2025-65552
CRITICAL
D3D Wi-Fi Home Security System ZX-G12 v2.1.1 - Info Disclosure
CVSS 9.8
CVE-2025-69197
MEDIUM
Pterodactyl <1.11.11 - Info Disclosure
CVSS 6.5
CVE-2025-40807
MEDIUM
Gridscale X Prepay <V4.2.1 - Auth Bypass
CVSS 6.3
CVE-2025-30201
HIGH
Wazuh <4.13.0 - Privilege Escalation
CVSS 7.7
Details
Vulnerabilities
210
Exploit Likelihood
High