CWE-1392
92 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1392page 1 of 2
- CVE-2018-25147HIGHCVSS 7.5EG 7.52025-12-24
Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to the device by logging …
- CVE-2020-36915HIGHCVSS 7.5EG 7.52026-01-06
Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials to gain root-level …
- CVE-2021-47707CRITICALCVSS 9.3EG 0.02025-12-09
COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclose RTSP stream. Attackers can exploit this by sending a POST request with the 'passkey' parameter set to '1234', allowin…
- CVE-2022-50803CRITICALCVSS 9.8EG 9.82025-12-30
JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the device with administrative privileges.
- CVE-2023-30603CRITICALCVSS 9.8EG 9.82023-06-02
Hitron Technologies CODA-5310 Telnet function with the default account and password, and there is no warning or prompt to ask users to change the default password and account. An unauthenticated remote attackers can exploit this vulnerabil…
- CVE-2023-30801CRITICALCVSS 9.8EG 9.82023-10-10
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote at…
- CVE-2023-3703CRITICALCVSS 10.0EG 10.02023-09-03
Proscend Advice ICR Series routers FW version 1.76 - CWE-1392: Use of Default Credentials
- CVE-2023-40704MEDIUMCVSS 6.8EG 7.12024-07-18
The product does not require unique and complex passwords to be created during installation. Using Philips's default password could jeopardize the PACS system if the password was hacked or leaked. An attacker could gain access to the da…
- CVE-2023-43844HIGHCVSS 8.0EG 8.02024-05-28
Aten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged web interface account. The user is not asked to change the credentials after first login. If not changed, attackers can log in to the web interface and gain admini…
- CVE-2023-49621CRITICALCVSS 9.8EG 9.82024-01-09
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses default credential with admin privileges. An attacker could use the credentials to …
- CVE-2024-10476HIGHCVSS 8.0EG 8.02024-12-17
Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modify or delete data, including sensitive information such as protected health information (PHI) and per…
- CVE-2024-12013HIGHCVSS 7.6EG 7.62025-02-13
A CWE-1392 “Use of Default Credentials” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The device exposes an FTP server with default and easy-to-guess admin credentials. A remote attacker capable of …
- CVE-2024-12286CRITICALCVSS 9.8EG 9.82024-12-10
MOBATIME Network Master Clock - DTS 4801 allows attackers to use SSH to gain initial access using default credentials.
- CVE-2024-12856HIGHCVSS 7.2EG 7.22024-12-27
The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 allows authenticated and remote attackers to execute arbitrary OS commands over HTTP when …
- CVE-2024-12902HIGHCVSS 8.4EG 8.42024-12-23
ANCHOR from Global Wisdom Software is an integrated product running on a Windows virtual machine. The underlying Windows OS of the product contains high-privilege service accounts. If these accounts use default passwords, attackers could r…
- CVE-2024-13893HIGHCVSS 7.5EG 0.02025-03-06
Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, might share same credentials for telnet service. Hash of the password can be retrieved through physical access to SPI con…
- CVE-2024-27158HIGHCVSS 7.4EG 7.42024-06-14
All the Toshiba printers share the same hardcoded root password. As for the affected products/models/versions, see the reference URL.
- CVE-2024-28093HIGHCVSS 8.8EG 8.82024-03-26
The TELNET service of AdTran NetVanta 3120 18.01.01.00.E devices is enabled by default, and has default credentials for a root-level account.
- CVE-2024-29844CRITICALCVSS 9.8EG 7.52024-04-15
Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change…
- CVE-2024-30210HIGHCVSS 7.4EG 7.42024-04-12
IO-1020 Micro ELD uses a default WIFI password that could allow an adjacent attacker to connect to the device.
- CVE-2024-31069HIGHCVSS 7.4EG 7.42024-04-12
IO-1020 Micro ELD web server uses a default password for authentication.
- CVE-2024-39584HIGHCVSS 8.2EG 8.22024-08-28
Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Secure Boot bypass and arbitrary code execution.
- CVE-2024-39747HIGHCVSS 8.1EG 8.12024-08-31
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.
- CVE-2024-4007HIGHCVSS 8.8EG 8.82024-07-01
Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.
- CVE-2024-40113MEDIUMCVSS 6.5EG 6.52025-06-02
Sitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials.
- CVE-2024-45068HIGHCVSS 7.1EG 7.12024-12-03
Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.3-00; Hitachi Ops Center OVA: from 10…
- CVE-2024-4622HIGHCVSS 8.3EG 0.02024-05-15
If misconfigured, alpitronic Hypercharger EV charging devices can expose a web interface protected by authentication. If the default credentials are not changed, an attacker can use public knowledge to access the device as an administra…
- CVE-2024-46899HIGHCVSS 7.1EG 7.12025-04-22
Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentials leakage vulnerability.This issue affects Hitachi Ops Center Common Services: from 10.0.0-00 before 11.0.0-04; Hitach…
- CVE-2024-5245HIGHCVSS 7.8EG 7.82024-05-23
NETGEAR ProSAFE Network Management System Default Credentials Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System…
- CVE-2024-54015HIGHCVSS 7.5EG 7.52025-02-11
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 6MD86 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 6MD89 (CP300) (All versi…
- CVE-2024-5632MEDIUMCVSS 5.3EG 0.02024-07-09
Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, create a WiFi network with a default password. A user is neither advised to change it during the installation process, nor such a need is de…
- CVE-2024-6245HIGHCVSS 7.4EG 6.72024-10-28
Use of Default Credentials vulnerability in Maruti Suzuki SmartPlay on Linux (Infotainment Hub modules) allows attacker to try common or default usernames and passwords.The issue was detected on a 2022 Maruti Suzuki Brezza in India Market.…
- CVE-2024-6535MEDIUMCVSS 5.3EG 5.32024-07-17
A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift oauth-proxy with a static cookie-secret. In certain circumstances, this may allow an atta…
- CVE-2024-6788HIGHCVSS 8.6EG 8.62024-08-13
A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password.
- CVE-2024-7746CRITICALCVSS 9.8EG 9.82024-08-13
Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the Traccar solution that should otherwi…
- CVE-2024-7898HIGHCVSS 7.3EG 7.32024-08-17
A vulnerability classified as critical was found in Tosei Online Store Management System ネット店舗管理システム 4.02/4.03/4.04. This vulnerability affects unknown code of the component Backend. The manipulation leads to use of d…
- CVE-2025-0482HIGHCVSS 7.3EG 7.32025-01-15
A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. This affects an unknown part of the file /fladmin/user_recoverpwd.php. The manipulation leads to use of default credentials. It is possible to in…
- CVE-2025-10542CRITICALCVSS 9.8EG 9.82025-09-25
iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s connection dialog. If the administrator does not change these defaults, a remote attacker can authenticate to the EA…
- CVE-2025-10678CRITICALCVSS 9.3EG 0.02025-10-20
NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL. This issue affects instances installed using vendor's provided script. This issue may affect inst…
- CVE-2025-1160HIGHCVSS 7.3EG 7.32025-02-10
A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument username/password leads…
- CVE-2025-11943HIGHCVSS 7.3EG 7.32025-10-19
A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality of the component HTTP Web Server. The manipulation leads to use of default credentials. The attack can be initiated rem…
- CVE-2025-12217CRITICALCVSS 9.1EG 9.12025-10-25
SNMP Default Community String (public).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- CVE-2025-12218CRITICALCVSS 9.1EG 9.12025-10-25
Weak Default Credentials.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- CVE-2025-12592CRITICALCVSS 9.3EG 0.02025-11-19
Legacy Vivotek Device firmware uses default credetials for the root and user login accounts.
- CVE-2025-1531MEDIUMCVSS 6.5EG 6.52025-05-16
Authentication credentials leakage vulnerability in Hitachi Ops Center Analyzer viewpoint.This issue affects Hitachi Ops Center Analyzer viewpoint: from 10.0.0-00 before 11.0.4-00.
- CVE-2025-1711MEDIUMCVSS 4.3EG 4.32025-07-03
Multiple services of the DUT as well as different scopes of the same service reuse the same credentials.
- CVE-2025-2119LOWCVSS 2.0EG 2.02025-03-09
A vulnerability was found in Thinkware Car Dashcam F800 Pro up to 20250226. It has been declared as problematic. This vulnerability affects unknown code of the component Device Registration Handler. The manipulation leads to use of default…
- CVE-2025-2184MEDIUMCVSS 5.3EG 0.02025-08-13
A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal service…
- CVE-2025-22460HIGHCVSS 7.8EG 7.82025-05-13
Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.
- CVE-2025-23012HIGHCVSS 7.5EG 7.52025-01-23
Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with default credentials and privileges to read read local files by manipulating datastreams. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer mainta…
Map vulnerabilities like CWE-1392 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1392 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →