Weaknesses of type CWE-1188

214 results

Padrão inseguro que deveria ser alterado pelo administrador

O software sai da fábrica com configurações padrão inseguras (senhas fracas, portas abertas, protocolos desabilitados) que o administrador precisaria mudar manualmente. O problema é quando o desenvolvedor assume que essa mudança vai acontecer e não força o usuário a fazer isso na primeira execução, deixando sistemas desprotegidos em produção.

Example

Um servidor web vem com credenciais padrão (admin/admin) e a documentação diz 'altere na primeira inicialização'. Mas o admin esquece ou não lê, e o sistema fica acessível com essas credenciais conhecidas publicamente, permitindo invasão imediata.

How to mitigate

Force a mudança de configurações críticas na primeira inicialização (modo setup obrigatório), gere padrões fortes automaticamente (senhas aleatórias) ou desabilite recursos perigosos por padrão, exigindo ativação explícita do admin com reconhecimento dos riscos.

CVE-2026-93338MEDIUMGrandstream GWN7660ELR < 1.0.27.6 Information Disclosure via SNMP Default Community StringEPSS 0.3%CVE-2025-35021MEDIUMAbilis CPX Fallback Shell Connection RelayEPSS 0.3%CVE-2026-63563MEDIUMSharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in EPSS 0.3%CVE-2026-45728HIGHAlgernon: Single-file mode unconditionally enables debug modeEPSS 0.3%CVE-2025-64135MEDIUMJenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` EPSS 0.3%CVE-2025-53602MEDIUMZipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-2025-48927.EPSS 0.3%CVE-2026-6866HIGHInitialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel ServerEPSS 0.3%CVE-2026-32046MEDIUMOpenClaw < 2026.2.21 - OS-level Sandbox Bypass via --no-sandbox FlagEPSS 0.3%CVE-2025-25271HIGHOCPP Backend Configuration via Insecure DefaultsEPSS 0.3%CVE-2022-2196MEDIUMSpeculative execution attacks in KVM VMXEPSS 0.3%CVE-2026-53507HIGHoasdiff actions resolve external $refs by default, enabling SSRF and disclosure of structured files on pull-request runsEPSS 0.3%CVE-2025-61481CRITICALAn issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an oEPSS 0.3%CVE-2026-33376HIGHAuth Proxy IPv6 whitelist bypassEPSS 0.3%CVE-2026-49462MEDIUMnl.nl-portal:app has GraphiQL UI and GraphQL schema introspection enabled by defaultEPSS 0.3%CVE-2026-43527MEDIUMOpenClaw < 2026.4.14 - Server-Side Request Forgery via Private Network NavigationEPSS 0.3%CVE-2026-44892HIGHNetty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header SizeEPSS 0.3%CVE-2025-31930HIGHA vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions < V2.135), IEC 1Ph 7.4kW Child socket/ EPSS 0.3%CVE-2025-29985MEDIUMDell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Initialization of a Resource with an Insecure Default vulnerability in the EPSS 0.3%CVE-2026-9262HIGHUse of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlierEPSS 0.3%CVE-2026-43892HIGHAntSword: Incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injectionEPSS 0.3%