Weaknesses of type CWE-1188

214 results

Padrão inseguro que deveria ser alterado pelo administrador

O software sai da fábrica com configurações padrão inseguras (senhas fracas, portas abertas, protocolos desabilitados) que o administrador precisaria mudar manualmente. O problema é quando o desenvolvedor assume que essa mudança vai acontecer e não força o usuário a fazer isso na primeira execução, deixando sistemas desprotegidos em produção.

Example

Um servidor web vem com credenciais padrão (admin/admin) e a documentação diz 'altere na primeira inicialização'. Mas o admin esquece ou não lê, e o sistema fica acessível com essas credenciais conhecidas publicamente, permitindo invasão imediata.

How to mitigate

Force a mudança de configurações críticas na primeira inicialização (modo setup obrigatório), gere padrões fortes automaticamente (senhas aleatórias) ou desabilite recursos perigosos por padrão, exigindo ativação explícita do admin com reconhecimento dos riscos.

CVE-2023-48733MEDIUMAn insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure BootEPSS 0.3%CVE-2021-33130MEDIUMInsecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before version 2.6.0.74 may allow an unauthenticated useEPSS 0.3%CVE-2025-43015HIGHIn JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfacesEPSS 0.3%CVE-2024-5801MEDIUMIP Forwarding enabled in B&R Automation RuntimeEPSS 0.3%CVE-2025-2442MEDIUMCWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could potentially lead to unauthorized access whicEPSS 0.2%CVE-2026-41931MEDIUMVvveb < 1.0.8.2 Information Disclosure via Debug Exception HandlerEPSS 0.2%CVE-2025-43797MEDIUMIn Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through EPSS 0.2%CVE-2026-77348HIGHWallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php`EPSS 0.2%CVE-2026-65881HIGHJoomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1EPSS 0.2%CVE-2026-9680MEDIUMMCP Server Exposure via Insecure Default Binding on alibabacloud-rds-openapi-mcp-serverEPSS 0.2%CVE-2022-24287HIGHA vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC06), SIMATIC PCS 7 VEPSS 0.2%CVE-2026-75062CRITICALEval Injection in google/langfun via default lf.query protocolEPSS 0.2%CVE-2026-40994HIGHWss4jSecurityInterceptor disables WS-I BSP validation by defaultEPSS 0.2%CVE-2026-54800MEDIUMA vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < VEPSS 0.2%CVE-2026-33072HIGHFileRise: Default Encryption Key Enables Token Forgery and Config DecryptionEPSS 0.2%CVE-2025-2441MEDIUMCWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could lead to loss of confidentiality when a malicEPSS 0.2%CVE-2025-62802MEDIUMDNN CKEditor Provider allows unauthenticated upload out-of-the-boxEPSS 0.2%CVE-2026-20265MEDIUMInsecure Default Domain Allowlist in Splunk AI ToolkitEPSS 0.2%CVE-2024-8313HIGHDefault or Guessable SNMP community names in B&R APROLEPSS 0.2%CVE-2026-43581CRITICALOpenClaw < 2026.4.10 - Chrome DevTools Protocol Exposure via Overly Broad CDP Relay BindingEPSS 0.2%