Weaknesses of type CWE-1392

116 results

Uso de Credenciais Padrão

A aplicação ou serviço é implantado com credenciais (usuários, senhas, chaves) pré-configuradas e conhecidas publicamente, sem obrigar a mudança na primeira inicialização. Um atacante externo consegue acessar funcionalidades sensíveis usando essas credenciais padrão, contornando completamente o controle de acesso.

Example

Um roteador, câmera IP ou painel administrativo vem com user 'admin' e senha 'admin' ou '12345'. Se o usuário não trocar essas credenciais durante a configuração, qualquer pessoa na internet que conhecer o padrão consegue fazer login e comprometer o dispositivo ou rede.

How to mitigate

Force a mudança de credenciais padrão na primeira execução, bloqueando acesso até que novas credenciais sejam definidas. Para sistemas já em produção, desative ou remova contas padrão e implemente senhas fortes geradas aleatoriamente para cada instalação, nunca documentadas em público.

CVE-2025-54303CRITICALThe Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API.EPSS 0.4%CVE-2026-31837HIGHIstio JWKS resolver to prevent private key material from being exposed when JWKS fetch fails.EPSS 0.4%CVE-2020-36915HIGHAdtec Digital SignEdje Digital Signage Player v2.08.28 Default CredentialsEPSS 0.4%CVE-2026-22273HIGHDell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default Credentials vulnerabiEPSS 0.4%CVE-2021-47707CRITICALCOMMAX CVD-Axx DVR Weak Default Credentials Stream DisclosureEPSS 0.4%CVE-2026-86464CRITICALIn the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deploEPSS 0.4%CVE-2025-1711MEDIUMCVE-2025-1711EPSS 0.3%CVE-2025-54137HIGHNodeJS version of the HAX CMS application is distributed with Default SecretsEPSS 0.3%CVE-2024-12013HIGHA CWE-1392 “Use of Default Credentials” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The device exposeEPSS 0.3%CVE-2025-55051CRITICALCWE-1392: Use of Default CredentialsEPSS 0.3%CVE-2023-40704MEDIUMPhilips Vue PACS Use of Default CredentialsEPSS 0.3%CVE-2025-35114HIGHAgiloft local privilege escalation via default credentialsEPSS 0.3%CVE-2025-12592CRITICALUse of default login credentials in Legacy Vivotek DevicesEPSS 0.3%CVE-2024-30210HIGHIOSIX IO-1020 Micro ELD Use of Default CredentialsEPSS 0.3%CVE-2026-90451HIGHAn example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled EPSS 0.3%CVE-2025-22460HIGHDefault credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privilEPSS 0.3%CVE-2026-90940MEDIUMnovel-plus through 5.3.3 Default Cache Management Password in the Front PortalEPSS 0.3%CVE-2024-46899HIGHAuthentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVFEPSS 0.3%CVE-2024-45068HIGHAuthentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVAEPSS 0.3%CVE-2026-76155CRITICALDatiphy Data Management Center - Use of Default CredentialsEPSS 0.3%