Weaknesses of type CWE-1188

215 results

Padrão inseguro que deveria ser alterado pelo administrador

O software sai da fábrica com configurações padrão inseguras (senhas fracas, portas abertas, protocolos desabilitados) que o administrador precisaria mudar manualmente. O problema é quando o desenvolvedor assume que essa mudança vai acontecer e não força o usuário a fazer isso na primeira execução, deixando sistemas desprotegidos em produção.

Example

Um servidor web vem com credenciais padrão (admin/admin) e a documentação diz 'altere na primeira inicialização'. Mas o admin esquece ou não lê, e o sistema fica acessível com essas credenciais conhecidas publicamente, permitindo invasão imediata.

How to mitigate

Force a mudança de configurações críticas na primeira inicialização (modo setup obrigatório), gere padrões fortes automaticamente (senhas aleatórias) ou desabilite recursos perigosos por padrão, exigindo ativação explícita do admin com reconhecimento dos riscos.

CVE-2023-33949MEDIUMIn Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email EPSS 0.8%CVE-2024-47295HIGHInsecure initial password configuration issue in SEIKO EPSON Web Config allows a remote unauthenticated attacker to set an arbitrary passworEPSS 0.8%CVE-2025-7353CRITICALRockwell Automation ControlLogix® Ethernet Remote Code Execution VulnerabilityEPSS 0.8%CVE-2026-25894CRITICALFUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default ConfigurationEPSS 0.8%CVE-2026-47393CRITICALPraisonAI `deploy --type api` emits a Flask server with authentication disabled by defaultEPSS 0.8%CVE-2026-57147CRITICALpraisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgeryEPSS 0.8%CVE-2024-31070CRITICALInitialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century SEPSS 0.8%CVE-2022-41648CRITICALThe HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CEPSS 0.7%CVE-2025-1863CRITICALInsecure default settings for recorder productsEPSS 0.7%CVE-2024-45217HIGHApache Solr: ConfigSets created during a backup restore command are trusted implicitlyEPSS 0.7%CVE-2022-3262HIGHA flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. ThEPSS 0.7%CVE-2025-41438CRITICALConsilium Safety CS5000 Fire Panel Initialization of a Resource with an Insecure DefaultEPSS 0.7%CVE-2026-44109CRITICALOpenClaw < 2026.4.15 - Authentication Bypass in Feishu Webhook and Card-Action ValidationEPSS 0.7%CVE-2026-33037HIGHWWBN AVideo has predictable default admin credentials in official Docker deployment pathEPSS 0.7%CVE-2021-35535HIGHInsufficient Security Control VulnerabilityEPSS 0.7%CVE-2025-47945CRITICALDonetick Has Weak Default JWT SecretEPSS 0.7%CVE-2025-59097CRITICALUnauthenticated SOAP API in dormakaba access managerEPSS 0.7%CVE-2024-8383HIGHFirefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does noEPSS 0.6%CVE-2025-41245MEDIUMVMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)EPSS 0.6%CVE-2026-55454CRITICALAppsmith: Caddy admin API exposed without authenticationEPSS 0.6%