Description
admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can recover plaintext passwords through offline dictionary or brute-force attacks due to negligible computational effort.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 17 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can recover plaintext passwords through offline dictionary or brute-force attacks due to negligible computational effort. | |
| Title | admin3 through 3.0.0 Weak Password Hashing via Single-Round MD5 | |
| Weaknesses | CWE-916 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T12:33:25.228Z
Reserved: 2026-09-17T11:07:29.772Z
Link: CVE-2026-92921
No data.
Status : Received
Published: 2026-09-17T13:17:01.467
Modified: 2026-09-17T13:17:01.467
Link: CVE-2026-92921
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-916
Use of Password Hash With Insufficient Computational Effort