Fallos del tipo CWE-1392

116 resultados

Uso de credenciais padrão

A aplicação ou sistema é instalado ou deployado com credenciais (usuário e senha) pré-configuradas que nunca são alteradas. Um atacante consegue acessar a aplicação ou recurso usando essas credenciais conhecidas publicamente, contornando completamente autenticação e controle de acesso.

Ejemplo

Um roteador ou câmera IP sai da fábrica com login admin/admin. Se o responsável não trocar a senha no setup, qualquer pessoa que conhece essas credenciais padrão (fácil de achar em manual ou fórum) consegue acessar e reconfigurar o dispositivo.

Cómo mitigar

Force alteração de credenciais padrão durante o primeiro acesso ou setup inicial — bloqueie qualquer operação além da autenticação até que a senha seja trocada. Em ambiente corporativo, use gestão centralizada de credenciais e audite regularmente contas com padrões conhecidos.

CVE-2025-29525MEDIUMDASAN GPON ONU H660WM OS version H660WMR210825 Hardware version DS-E5-583-A1 was discovered to contain insecure default credentials in the mEPSS 0.3%CVE-2025-2341LOWIROAD Dash Cam X5 SSID default credentialsEPSS 0.3%CVE-2026-90498MEDIUMlenve vhr vhr.sql default credentialsEPSS 0.3%CVE-2024-40113MEDIUMSitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials.EPSS 0.3%CVE-2025-12217MEDIUMSNMP Default Community String (public)EPSS 0.3%CVE-2025-12218CRITICALWeak Default CredentialsEPSS 0.3%CVE-2024-27158HIGHHardcoded root passwordEPSS 0.3%CVE-2025-36221MEDIUMVulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops.EPSS 0.3%CVE-2026-45039CRITICALRustFS: Internode RPC HMAC secret falls back to public default credential, enabling peer impersonationEPSS 0.3%CVE-2025-1531MEDIUMAuthentication credentials leakage vulnerability in Hitachi Ops Center Analyzer viewpoint OVFEPSS 0.3%CVE-2025-6951MEDIUMSAFECAM X300 FTP Service default credentialsEPSS 0.3%CVE-2025-2119LOWThinkware Car Dashcam F800 Pro Device Registration default credentialsEPSS 0.3%CVE-2026-90456CRITICALAn example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative pasEPSS 0.3%CVE-2024-5632MEDIUMLongse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, create a WiFi network with a default passwEPSS 0.2%CVE-2025-55740MEDIUMDefault Credentials in nginx-defender Configuration FilesEPSS 0.2%CVE-2026-9844HIGHVulnerability in navify® Digital PathologyEPSS 0.2%CVE-2026-7428CRITICALInsecure default administrative credentials in AlloyDB for PostgreSQLEPSS 0.2%CVE-2024-10476HIGHDefault credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modifyEPSS 0.2%CVE-2026-42941HIGHMacGregor Voyage Data Recorder (VDR) G4e Use of Default CredentialsEPSS 0.2%CVE-2025-9576LOWseeedstudio ReSpeaker Administrative shadow default credentialsEPSS 0.2%