← Vulnerability feed

Vulnerability record · CVE-2021-43298 · published 25 January 2022

CVE-2021-43298: Embedthis goahead improper restriction of authentication attempts vulnerability

Embedthis · Goahead

The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that an unauthenticated network attacker can brute-force the HTTP basic password, byte-by-byte, by recording the webserver's response time until the unauthorized (401) response.

9.8 CVSS 3.1 Critical EPSS 2.3% · top 17.7% CWE-208 · CWE-208CWE-307 · Improper restriction of authentication attempts
9.8CVSS 3.1 base score, v2 5.0
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that an unauthenticated network attacker can brute-force the HTTP basic password, byte-by-byte, by recording the webserver's response time until the unauthorized (401) response.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-43298 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2017-17562Embedthis GoAhead CGI environment variable injection enables remote code executionEmbedthis GoAhead before 3.6.5 initializes the environment of forked CGI scripts using untrusted HTTP request parameters in cgiHandler in cgi.c. When…KEVEPSS 96%analysed9.8CVE-2021-41615Embedthis goahead vulnerabilitywebsda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparadise valu…EPSS 1.4%9.8CVE-2021-42342GoAhead file upload filter allows environment variable injection into CGI scriptsGoAhead 4.x and 5.x before 5.1.5 fail to prefix user form variables with the CGI prefix in the file upload filter, letting untrusted environment vari…EPSS 59%analysed9.8CVE-2019-5096GoAhead web server use-after-free in multipart/form-data handlingGoAhead versions 5.0.1, 4.1.1 and 3.6.5 contain a use-after-free when processing multipart/form-data requests. A crafted HTTP request corrupts heap s…EPSS 67%analysed9.8CVE-2017-1000471Embedthis goahead null pointer dereference vulnerabilityEmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of …EPSS 8.6%9.8CVE-2017-5674Embedthis goahead information exposure vulnerabilityA vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft …EPSS 22%8.8CVE-2020-15688Embedthis goahead authentication bypass by capture-replay vulnerabilityThe HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthentica…EPSS 4.0%8.8CVE-2017-5675Embedthis goahead command injection vulnerabilityA command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2021-43298), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.