Fallos del tipo CWE-1188

213 resultados

Padrão inseguro não alterado pelo administrador

A aplicação é entregue com configurações padrão fracas (senhas genéricas, portas abertas, debug ativo) que *deveriam* ser alteradas durante a instalação ou pós-deployement, mas muitas vezes não são. O atacante explora essas configurações padrão conhecidas para ganhar acesso ou comprometer a aplicação sem precisar quebrar nenhuma segurança real.

Ejemplo

Um NAS é instalado com senha padrão 'admin:admin' que o fabricante documenta como 'por favor mude na primeira inicialização'. Muitos usuários nunca fazem isso, e o atacante usa essa credencial padrão para acessar centenas de dispositivos. Outro caso: aplicação web deixa console de debug ativado por padrão em produção, expondo informações sensíveis.

Cómo mitigar

Força o usuário a alterar configurações críticas (senha, chaves de API) durante o primeiro acesso, bloqueando a continuidade até que sejam mudadas. Em produção, desative completamente recursos de debug e funcionalidades administrativas por padrão; exija ativação explícita com autenticação forte.

CVE-2026-93338MEDIUMGrandstream GWN7660ELR < 1.0.27.6 Information Disclosure via SNMP Default Community StringEPSS 0.3%CVE-2025-35021MEDIUMAbilis CPX Fallback Shell Connection RelayEPSS 0.3%CVE-2026-45728HIGHAlgernon: Single-file mode unconditionally enables debug modeEPSS 0.3%CVE-2026-63563MEDIUMSharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in EPSS 0.3%CVE-2025-64135MEDIUMJenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` EPSS 0.3%CVE-2025-53602MEDIUMZipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-2025-48927.EPSS 0.3%CVE-2026-6866HIGHInitialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel ServerEPSS 0.3%CVE-2026-32046MEDIUMOpenClaw < 2026.2.21 - OS-level Sandbox Bypass via --no-sandbox FlagEPSS 0.3%CVE-2025-25271HIGHOCPP Backend Configuration via Insecure DefaultsEPSS 0.3%CVE-2022-2196MEDIUMSpeculative execution attacks in KVM VMXEPSS 0.3%CVE-2026-53507HIGHoasdiff actions resolve external $refs by default, enabling SSRF and disclosure of structured files on pull-request runsEPSS 0.3%CVE-2025-61481CRITICALAn issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an oEPSS 0.3%CVE-2026-33376HIGHAuth Proxy IPv6 whitelist bypassEPSS 0.3%CVE-2026-49462MEDIUMnl.nl-portal:app has GraphiQL UI and GraphQL schema introspection enabled by defaultEPSS 0.3%CVE-2026-43527MEDIUMOpenClaw < 2026.4.14 - Server-Side Request Forgery via Private Network NavigationEPSS 0.3%CVE-2026-44892HIGHNetty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header SizeEPSS 0.3%CVE-2025-31930HIGHA vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions < V2.135), IEC 1Ph 7.4kW Child socket/ EPSS 0.3%CVE-2025-29985MEDIUMDell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Initialization of a Resource with an Insecure Default vulnerability in the EPSS 0.3%CVE-2026-9262HIGHUse of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlierEPSS 0.3%CVE-2026-43892HIGHAntSword: Incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injectionEPSS 0.3%