Weaknesses of type CWE-1188

214 results

Padrão inseguro que deveria ser alterado pelo administrador

O software sai da fábrica com configurações padrão inseguras (senhas fracas, portas abertas, protocolos desabilitados) que o administrador precisaria mudar manualmente. O problema é quando o desenvolvedor assume que essa mudança vai acontecer e não força o usuário a fazer isso na primeira execução, deixando sistemas desprotegidos em produção.

Example

Um servidor web vem com credenciais padrão (admin/admin) e a documentação diz 'altere na primeira inicialização'. Mas o admin esquece ou não lê, e o sistema fica acessível com essas credenciais conhecidas publicamente, permitindo invasão imediata.

How to mitigate

Force a mudança de configurações críticas na primeira inicialização (modo setup obrigatório), gere padrões fortes automaticamente (senhas aleatórias) ou desabilite recursos perigosos por padrão, exigindo ativação explícita do admin com reconhecimento dos riscos.

CVE-2026-57148CRITICALpraisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)EPSS 0.4%CVE-2025-41672CRITICALWAGO: Vulnerability in WAGO Device SphereEPSS 0.4%CVE-2026-62416MEDIUMNetwork Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication EPSS 0.4%CVE-2026-1675MEDIUMAdvanced Country Blocker <= 2.3.1 - Unauthenticated Authorization Bypass via Insecure Default Secret KeyEPSS 0.4%CVE-2026-86464CRITICALIn the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deploEPSS 0.4%CVE-2026-16504CRITICALVPS.org one-click Zulip template deployment instance contains multiple vulnerabilitiesEPSS 0.4%CVE-2026-24148HIGHNVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initiaEPSS 0.3%CVE-2026-32965HIGHInitialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provided by silex technology, Inc. WhEPSS 0.3%CVE-2026-30805CRITICALInsecure Default Initialization in API Authentication leads to Authentication BypassEPSS 0.3%CVE-2024-45313MEDIUMInsecure default setting for Server Pro installed via Overleaf toolkitEPSS 0.3%CVE-2026-55581HIGHmcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` ExecutableEPSS 0.3%CVE-2018-25169HIGHAMPPS 2.7 Denial of Service via Malformed Socket ConnectionEPSS 0.3%CVE-2025-66482MEDIUMMisskey has a login rate limit bypass via spoofed X-Forwarded-For headerEPSS 0.3%CVE-2023-3453HIGHETIC Telecom Insecure Default Initialization of ResourceEPSS 0.3%CVE-2018-25193HIGHMongoose Web Server 6.9 Denial of Service via Socket ConnectionEPSS 0.3%CVE-2026-53660HIGHOpenAM Insecure SSO Cookie InitializationEPSS 0.3%CVE-2024-25972HIGHInitialization of a resource with an insecure default vulnerability in OET-213H-BTS1 sold in Japan by Atsumi Electric Co., Ltd. allows a netEPSS 0.3%CVE-2026-34780HIGHElectron: Context Isolation bypass via contextBridge VideoFrame transferEPSS 0.3%CVE-2026-16503CRITICALVPS.org one-click Supabase template deployment instance contains multiple vulnerabilitiesEPSS 0.3%CVE-2022-48342MEDIUMIn JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.EPSS 0.3%