Weaknesses of type CWE-1188

214 results

Padrão inseguro que deveria ser alterado pelo administrador

O software sai da fábrica com configurações padrão inseguras (senhas fracas, portas abertas, protocolos desabilitados) que o administrador precisaria mudar manualmente. O problema é quando o desenvolvedor assume que essa mudança vai acontecer e não força o usuário a fazer isso na primeira execução, deixando sistemas desprotegidos em produção.

Example

Um servidor web vem com credenciais padrão (admin/admin) e a documentação diz 'altere na primeira inicialização'. Mas o admin esquece ou não lê, e o sistema fica acessível com essas credenciais conhecidas publicamente, permitindo invasão imediata.

How to mitigate

Force a mudança de configurações críticas na primeira inicialização (modo setup obrigatório), gere padrões fortes automaticamente (senhas aleatórias) ou desabilite recursos perigosos por padrão, exigindo ativação explícita do admin com reconhecimento dos riscos.

CVE-2025-64781MEDIUMIn GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1, "External pEPSS 0.2%CVE-2026-9039HIGHInitialization of a resource with an insecure default in XCharge C6EPSS 0.2%CVE-2026-46430MEDIUMAlgernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOSEPSS 0.2%CVE-2025-27809MEDIUMMbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unlEPSS 0.2%CVE-2026-54359HIGHMISP automation endpoints may be exposed to CSRF when Sec-Fetch-Site protection is disabled by defaultEPSS 0.2%CVE-2025-14758MEDIUMInitialization of a Resource with an Insecure Default in YAOOKEPSS 0.2%CVE-2025-52622MEDIUMHCL BigFix SaaS Remediate is affected by a security vulnerabilityEPSS 0.2%CVE-2025-31974LOWHCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-OnlyEPSS 0.2%CVE-2026-54907MEDIUMCaddy Proxy Manager: Registrations enabled by default allows creating users with "user" permissionEPSS 0.2%CVE-2025-5591HIGHStored Cross-site Scripting (XSS) in Kentico Xperience 13EPSS 0.2%CVE-2024-22388MEDIUMInsecure Default Initialization of Resource in HID GlobalEPSS 0.2%CVE-2024-30124MEDIUMHCL Sametime is impacted by insecure servicesEPSS 0.2%CVE-2023-3485LOWInsecure Default Authorization in Temporal ServerEPSS 0.2%CVE-2024-48122MEDIUMInsecure default configurations in HI-SCAN 6040i Hitrax HX-03-19-I allow authenticated attackers with low-level privileges to escalate to roEPSS 0.2%CVE-2025-27443LOWZoom Workplace Apps for Windows - Insecure Default Variable InitializationEPSS 0.2%CVE-2026-46517HIGHLMDeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-outEPSS 0.2%CVE-2026-24197MEDIUMNVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default iniEPSS 0.2%CVE-2022-48432MEDIUMIn JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.EPSS 0.2%CVE-2026-55708LOWPrivacy/configuration issue when adding local data in views through 'unbound-control'EPSS 0.1%CVE-2026-75926CRITICALHugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process GrantEPSS 0.1%