Weaknesses of type CWE-1393
46 resultsUso de Senha Padrão
A aplicação ou dispositivo é distribuído com uma senha padrão conhecida e o desenvolvedor não força sua alteração obrigatória na primeira inicialização. Um atacante pode usar essa senha pública para acessar funções administrativas ou sensíveis sem autenticação legítima.
Example
Um roteador é vendido com usuário 'admin' e senha 'admin123'. Se o firmware não obriga troca na primeira conexão, qualquer pessoa na rede consegue acessar as configurações e redirecionar tráfego ou desabilitar segurança.
How to mitigate
Force alteração obrigatória de credenciais padrão no primeiro acesso (setup wizard). Não distribua documentação com senhas padrão em produção e, se usar credenciais de fábrica, gere-as únicas por dispositivo ou nunca permita acesso remoto sem mudança prévia.
CVE-2023-45249CRITICALRemote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before buiEPSS 53.3%KEVCVE-2024-29021CRITICALSSRF into Sandbox Escape through Unsafe Default ConfigurationEPSS 20.2%CVE-2025-26793CRITICALThe Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (usernEPSS 2.4%CVE-2026-2635HIGHMLflow Use of Default Password Authentication Bypass VulnerabilityEPSS 1.2%CVE-2024-48987MEDIUMSnipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exaceEPSS 1.0%CVE-2023-25131CRITICALUse of default password vulnerability in CyberPower PowerPanel BusinessEPSS 1.0%CVE-2024-43659HIGHPlaintext default credentials in firmwareEPSS 0.8%CVE-2024-29666CRITICALInsecure Permissions vulnerability in Vehicle Monitoring platform system CMSV6 v.7.31.0.2 through v.7.32.0.3 allows a remote attacker to escEPSS 0.7%CVE-2023-24049CRITICALAn issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credentEPSS 0.7%CVE-2023-43042HIGHIBM Storage Virtualize information disclosureEPSS 0.7%CVE-2024-50588CRITICALUnprotected Exposed Firebird Database with default credentialsEPSS 0.7%CVE-2022-4126CRITICALUse of Default PasswordEPSS 0.6%CVE-2023-32090CRITICALPega platform clients who are using versions 6.1 through 7.3.1 may be
utilizing default credentials
EPSS 0.6%CVE-2026-35075CRITICALHardcoded default Password for Service AccountEPSS 0.6%CVE-2026-4404CRITICALUse of hard coded credentials in GoHarbor HarborEPSS 0.6%CVE-2025-8077CRITICALNeuVector admin account has insecure default passwordEPSS 0.6%CVE-2025-22938CRITICALAdtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords.EPSS 0.5%CVE-2026-82698MEDIUMsambitraj Student-Management-System aca.sql default passwordEPSS 0.5%CVE-2023-28094HIGHPega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credenEPSS 0.5%CVE-2026-69657CRITICALXING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected deviEPSS 0.5%