Weaknesses of type CWE-1392

116 results

Uso de Credenciais Padrão

A aplicação ou serviço é implantado com credenciais (usuários, senhas, chaves) pré-configuradas e conhecidas publicamente, sem obrigar a mudança na primeira inicialização. Um atacante externo consegue acessar funcionalidades sensíveis usando essas credenciais padrão, contornando completamente o controle de acesso.

Example

Um roteador, câmera IP ou painel administrativo vem com user 'admin' e senha 'admin' ou '12345'. Se o usuário não trocar essas credenciais durante a configuração, qualquer pessoa na internet que conhecer o padrão consegue fazer login e comprometer o dispositivo ou rede.

How to mitigate

Force a mudança de credenciais padrão na primeira execução, bloqueando acesso até que novas credenciais sejam definidas. Para sistemas já em produção, desative ou remova contas padrão e implemente senhas fortes geradas aleatoriamente para cada instalação, nunca documentadas em público.

CVE-2025-9577LOWTOTOLINK X2000R Administrative shadow.sample default credentialsEPSS 0.2%CVE-2024-6245HIGHDefault Credentials in ssh service for SmartPlay in Maruti SuzukiEPSS 0.2%CVE-2024-39584HIGHDell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with local access could potEPSS 0.2%CVE-2026-50005HIGHBrickcom Cameras Use of Default CredentialsEPSS 0.2%CVE-2026-65313HIGHUse of hard-coded VNC credentials in the engineering-workstation provisioningEPSS 0.2%CVE-2025-2184MEDIUMCortex XDR Broker VM: Secrets Shared Across Multiple Broker VM ImagesEPSS 0.2%CVE-2025-7740HIGHUse of default credentials vulnerability in Hitachi Energy SuprOS productEPSS 0.2%CVE-2024-12902HIGHGlobal Wisdom Software ANCHOR - Undocumented Privileged AccountEPSS 0.2%CVE-2026-28713HIGHDefault credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyber Protect Cloud AgeEPSS 0.2%CVE-2024-13893HIGHShared credentials in Smartwares camerasEPSS 0.2%CVE-2026-44273MEDIUMDell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attackerEPSS 0.2%CVE-2025-58744MEDIUMHard-Coded Default Credentials Enable Document Archive Decryption in Milner ImageDirector CaptureEPSS 0.1%CVE-2025-55110MEDIUMBMC Control-M/Agent hardcoded default keystore passwordEPSS 0.1%CVE-2025-54756HIGHBrightSign Players Use of Default CredentialsEPSS 0.1%CVE-2026-7365HIGHIBM Operations Analytics - Log Analysis is affected by Information disclosure due to default passwords not being forced to be changed on post-installationEPSS 0.1%CVE-2026-32652HIGHDell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Credentials" vulnerability. A low privileged attacker with console aEPSS 0.1%