Fallos del tipo CWE-1188

213 resultados

Padrão inseguro não alterado pelo administrador

A aplicação é entregue com configurações padrão fracas (senhas genéricas, portas abertas, debug ativo) que *deveriam* ser alteradas durante a instalação ou pós-deployement, mas muitas vezes não são. O atacante explora essas configurações padrão conhecidas para ganhar acesso ou comprometer a aplicação sem precisar quebrar nenhuma segurança real.

Ejemplo

Um NAS é instalado com senha padrão 'admin:admin' que o fabricante documenta como 'por favor mude na primeira inicialização'. Muitos usuários nunca fazem isso, e o atacante usa essa credencial padrão para acessar centenas de dispositivos. Outro caso: aplicação web deixa console de debug ativado por padrão em produção, expondo informações sensíveis.

Cómo mitigar

Força o usuário a alterar configurações críticas (senha, chaves de API) durante o primeiro acesso, bloqueando a continuidade até que sejam mudadas. Em produção, desative completamente recursos de debug e funcionalidades administrativas por padrão; exija ativação explícita com autenticação forte.

CVE-2026-57148CRITICALpraisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)EPSS 0.4%CVE-2025-41672CRITICALWAGO: Vulnerability in WAGO Device SphereEPSS 0.4%CVE-2026-62416MEDIUMNetwork Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication EPSS 0.4%CVE-2026-1675MEDIUMAdvanced Country Blocker <= 2.3.1 - Unauthenticated Authorization Bypass via Insecure Default Secret KeyEPSS 0.4%CVE-2026-86464CRITICALIn the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deploEPSS 0.4%CVE-2026-16504CRITICALVPS.org one-click Zulip template deployment instance contains multiple vulnerabilitiesEPSS 0.4%CVE-2026-24148HIGHNVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initiaEPSS 0.3%CVE-2026-32965HIGHInitialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provided by silex technology, Inc. WhEPSS 0.3%CVE-2026-30805CRITICALInsecure Default Initialization in API Authentication leads to Authentication BypassEPSS 0.3%CVE-2024-45313MEDIUMInsecure default setting for Server Pro installed via Overleaf toolkitEPSS 0.3%CVE-2026-55581HIGHmcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` ExecutableEPSS 0.3%CVE-2018-25193HIGHMongoose Web Server 6.9 Denial of Service via Socket ConnectionEPSS 0.3%CVE-2018-25169HIGHAMPPS 2.7 Denial of Service via Malformed Socket ConnectionEPSS 0.3%CVE-2023-3453HIGHETIC Telecom Insecure Default Initialization of ResourceEPSS 0.3%CVE-2025-66482MEDIUMMisskey has a login rate limit bypass via spoofed X-Forwarded-For headerEPSS 0.3%CVE-2026-53660HIGHOpenAM Insecure SSO Cookie InitializationEPSS 0.3%CVE-2024-25972HIGHInitialization of a resource with an insecure default vulnerability in OET-213H-BTS1 sold in Japan by Atsumi Electric Co., Ltd. allows a netEPSS 0.3%CVE-2026-34780HIGHElectron: Context Isolation bypass via contextBridge VideoFrame transferEPSS 0.3%CVE-2026-16503CRITICALVPS.org one-click Supabase template deployment instance contains multiple vulnerabilitiesEPSS 0.3%CVE-2022-48342MEDIUMIn JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.EPSS 0.3%