Weaknesses of type CWE-1392

116 results

Uso de Credenciais Padrão

A aplicação ou serviço é implantado com credenciais (usuários, senhas, chaves) pré-configuradas e conhecidas publicamente, sem obrigar a mudança na primeira inicialização. Um atacante externo consegue acessar funcionalidades sensíveis usando essas credenciais padrão, contornando completamente o controle de acesso.

Example

Um roteador, câmera IP ou painel administrativo vem com user 'admin' e senha 'admin' ou '12345'. Se o usuário não trocar essas credenciais durante a configuração, qualquer pessoa na internet que conhecer o padrão consegue fazer login e comprometer o dispositivo ou rede.

How to mitigate

Force a mudança de credenciais padrão na primeira execução, bloqueando acesso até que novas credenciais sejam definidas. Para sistemas já em produção, desative ou remova contas padrão e implemente senhas fortes geradas aleatoriamente para cada instalação, nunca documentadas em público.

CVE-2025-29525MEDIUMDASAN GPON ONU H660WM OS version H660WMR210825 Hardware version DS-E5-583-A1 was discovered to contain insecure default credentials in the mEPSS 0.3%CVE-2025-2341LOWIROAD Dash Cam X5 SSID default credentialsEPSS 0.3%CVE-2026-90498MEDIUMlenve vhr vhr.sql default credentialsEPSS 0.3%CVE-2024-40113MEDIUMSitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials.EPSS 0.3%CVE-2025-12217MEDIUMSNMP Default Community String (public)EPSS 0.3%CVE-2025-12218CRITICALWeak Default CredentialsEPSS 0.3%CVE-2024-27158HIGHHardcoded root passwordEPSS 0.3%CVE-2025-36221MEDIUMVulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops.EPSS 0.3%CVE-2026-45039CRITICALRustFS: Internode RPC HMAC secret falls back to public default credential, enabling peer impersonationEPSS 0.3%CVE-2025-1531MEDIUMAuthentication credentials leakage vulnerability in Hitachi Ops Center Analyzer viewpoint OVFEPSS 0.3%CVE-2025-6951MEDIUMSAFECAM X300 FTP Service default credentialsEPSS 0.3%CVE-2025-2119LOWThinkware Car Dashcam F800 Pro Device Registration default credentialsEPSS 0.3%CVE-2026-90456CRITICALAn example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative pasEPSS 0.3%CVE-2024-5632MEDIUMLongse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, create a WiFi network with a default passwEPSS 0.2%CVE-2025-55740MEDIUMDefault Credentials in nginx-defender Configuration FilesEPSS 0.2%CVE-2026-9844HIGHVulnerability in navify® Digital PathologyEPSS 0.2%CVE-2026-7428CRITICALInsecure default administrative credentials in AlloyDB for PostgreSQLEPSS 0.2%CVE-2024-10476HIGHDefault credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modifyEPSS 0.2%CVE-2026-42941HIGHMacGregor Voyage Data Recorder (VDR) G4e Use of Default CredentialsEPSS 0.2%CVE-2025-9576LOWseeedstudio ReSpeaker Administrative shadow default credentialsEPSS 0.2%