Fallos del tipo CWE-1393

43 resultados

Uso de senha padrão

A fraqueza ocorre quando um software ou dispositivo é entregue com credenciais hardcoded ou padrão (tipo 'admin/admin' ou 'root/password') que não são forçadas a mudar na primeira execução. Um atacante consegue acesso não autorizado simplesmente usando essas credenciais públicas ou facilmente adivináveis.

Ejemplo

Um roteador de fibra é instalado com login padrão 'admin/12345'. O cliente não muda a senha e o aparelho fica exposto na internet — qualquer um consegue acessar o painel de controle e redirecionar o tráfego, fazer phishing ou desativar o modem.

Cómo mitigar

Força o usuário a definir uma senha forte na primeira inicialização ou deploy (never ship com credenciais padrão ativas). Se inevitável ter padrão, documente claramente e implemente mecanismos de bloqueio após tentativas falhas. Para defesa, altere imediatamente qualquer credencial padrão em produção e faça inventário de componentes que ainda usam padrões.

CVE-2023-45249CRITICALRemote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before buiEPSS 53.3%KEVCVE-2024-29021CRITICALSSRF into Sandbox Escape through Unsafe Default ConfigurationEPSS 20.2%CVE-2025-26793CRITICALThe Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (usernEPSS 2.3%CVE-2024-48987MEDIUMSnipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exaceEPSS 1.0%CVE-2023-25131CRITICALUse of default password vulnerability in CyberPower PowerPanel BusinessEPSS 1.0%CVE-2026-2635HIGHMLflow Use of Default Password Authentication Bypass VulnerabilityEPSS 1.0%CVE-2024-43659HIGHPlaintext default credentials in firmwareEPSS 0.8%CVE-2024-29666CRITICALInsecure Permissions vulnerability in Vehicle Monitoring platform system CMSV6 v.7.31.0.2 through v.7.32.0.3 allows a remote attacker to escEPSS 0.7%CVE-2023-24049CRITICALAn issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credentEPSS 0.7%CVE-2023-43042HIGHIBM Storage Virtualize information disclosureEPSS 0.7%CVE-2024-50588CRITICALUnprotected Exposed Firebird Database with default credentialsEPSS 0.7%CVE-2022-4126CRITICALUse of Default PasswordEPSS 0.6%CVE-2023-28094HIGHPega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credenEPSS 0.5%CVE-2025-22938CRITICALAdtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords.EPSS 0.5%CVE-2024-30802CRITICALAn issue in Vehicle Management System 7.31.0.3_20230412 allows an attacker to escalate privileges via the login.html component.EPSS 0.5%CVE-2025-8077CRITICALNeuVector admin account has insecure default passwordEPSS 0.5%CVE-2023-32090CRITICALPega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials EPSS 0.5%CVE-2026-4404CRITICALUse of hard coded credentials in GoHarbor HarborEPSS 0.5%CVE-2025-27690CRITICALDell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker withEPSS 0.5%CVE-2026-35075CRITICALHardcoded default Password for Service AccountEPSS 0.5%