Weaknesses of type CWE-1188

214 results

Padrão inseguro que deveria ser alterado pelo administrador

O software sai da fábrica com configurações padrão inseguras (senhas fracas, portas abertas, protocolos desabilitados) que o administrador precisaria mudar manualmente. O problema é quando o desenvolvedor assume que essa mudança vai acontecer e não força o usuário a fazer isso na primeira execução, deixando sistemas desprotegidos em produção.

Example

Um servidor web vem com credenciais padrão (admin/admin) e a documentação diz 'altere na primeira inicialização'. Mas o admin esquece ou não lê, e o sistema fica acessível com essas credenciais conhecidas publicamente, permitindo invasão imediata.

How to mitigate

Force a mudança de configurações críticas na primeira inicialização (modo setup obrigatório), gere padrões fortes automaticamente (senhas aleatórias) ou desabilite recursos perigosos por padrão, exigindo ativação explícita do admin com reconhecimento dos riscos.

CVE-2024-41975MEDIUMCODESYS (Edge) Gateway for Windows insecure defaultEPSS 0.4%CVE-2025-56332CRITICALAuthentication Bypass in fosrl/pangolin v1.6.2 and before allows attackers to access Pangolin resource via Insecure Default ConfigurationEPSS 0.4%CVE-2025-70998CRITICALUTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the telnet service, possiblEPSS 0.4%CVE-2026-48502HIGHMessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflowsEPSS 0.4%CVE-2022-48493—Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2022-48492—Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2026-61439HIGHPraisonAI before 4.6.78 Prompt Injection Defense BypassEPSS 0.4%CVE-2026-79394HIGHAn insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMTEPSS 0.4%CVE-2024-56433LOWshadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user EPSS 0.4%CVE-2026-57139CRITICALPraisonAI MCPServer exposes unauthenticated HTTP tools/callEPSS 0.4%CVE-2026-48509MEDIUMMessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodiesEPSS 0.4%CVE-2026-32617HIGHAnythingLLM Permissable CORS policyEPSS 0.4%CVE-2025-57295HIGHH3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user aEPSS 0.4%CVE-2026-77915CRITICALrConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.phpEPSS 0.4%CVE-2026-32305HIGHTraefik mTLS bypass via fragmented ClientHello SNI extraction failureEPSS 0.4%CVE-2025-54127CRITICALHAXcms's Insecure Default Configuration Leads to Unauthenticated AccessEPSS 0.4%CVE-2026-35672HIGHphpMyFAQ - Authentication Bypass via Empty API TokenEPSS 0.4%CVE-2026-31818CRITICALBudibase: Server-Side Request Forgery via REST Connector with Empty Default BlacklistEPSS 0.4%CVE-2025-36222HIGHIBM Fusion insecure default configurationEPSS 0.4%CVE-2025-41713MEDIUMWAGO: Vulnerability in hardware switch circuitEPSS 0.4%