Cyber Resilience

CWE · MITRE source

CWE-1025Comparison Using Wrong Factors

Abstraction: Base · CVEs in our corpus: 13

The code performs a comparison between two entities, but the comparison examines the wrong factors or characteristics of the entities, which can lead to incorrect results and resultant weaknesses.

Last updated: 20 August 2026 13:14 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SA-11 Developer Testing and Evaluation
  • PR.PS-06
  • SA-15 Development Process, Standards, and Tools
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2025-25306 6.49.30.00172025-03-10
CVE-2026-9800 6.18.10.00362026-06-25
CVE-2026-408806.08.10.00262026-04-21
CVE-2026-758405.87.50.00312026-08-18
CVE-2025-32464 5.16.80.00722025-04-09
CVE-2026-48860 4.96.50.00192026-06-10
CVE-2026-402274.76.20.00202026-04-10
CVE-2024-20342 4.65.80.00532024-10-23
CVE-2026-216914.35.40.00252026-01-07
CVE-2025-2887 3.74.50.00312025-03-27
CVE-2025-2888 3.74.50.00312025-03-27
CVE-2025-27839 2.73.20.00352025-03-08