Fallos del tipo CWE-1393

46 resultados

Uso de senha padrão

A fraqueza ocorre quando um software ou dispositivo é entregue com credenciais hardcoded ou padrão (tipo 'admin/admin' ou 'root/password') que não são forçadas a mudar na primeira execução. Um atacante consegue acesso não autorizado simplesmente usando essas credenciais públicas ou facilmente adivináveis.

Ejemplo

Um roteador de fibra é instalado com login padrão 'admin/12345'. O cliente não muda a senha e o aparelho fica exposto na internet — qualquer um consegue acessar o painel de controle e redirecionar o tráfego, fazer phishing ou desativar o modem.

Cómo mitigar

Força o usuário a definir uma senha forte na primeira inicialização ou deploy (never ship com credenciais padrão ativas). Se inevitável ter padrão, documente claramente e implemente mecanismos de bloqueio após tentativas falhas. Para defesa, altere imediatamente qualquer credencial padrão em produção e faça inventário de componentes que ainda usam padrões.

CVE-2026-35075CRITICALHardcoded default Password for Service AccountEPSS 0.5%CVE-2024-49559HIGHDell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password vulnerability. A loEPSS 0.5%CVE-2026-33784CRITICALJSI Virtual Lightweight Collector: Default password is not required to be changed which allows unauthorized high-privileged accessEPSS 0.5%CVE-2025-26701CRITICALAn issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use EPSS 0.5%CVE-2024-51555CRITICALForce Change of Default CredentialsEPSS 0.4%CVE-2026-22886CRITICALOpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a defaulEPSS 0.4%CVE-2026-24429CRITICALTenda W30E V2 Hardcoded Default Password for Built-in AccountEPSS 0.4%CVE-2024-13966MEDIUMZKTeco BioTime default passwordEPSS 0.4%CVE-2025-66050CRITICALNo password set for administrative account in Vivotek IP7137 camerasEPSS 0.4%CVE-2025-14917MEDIUMIBM WebSphere Application Server Liberty could provide weaker than expected securityEPSS 0.4%CVE-2026-16504CRITICALVPS.org one-click Zulip template deployment instance contains multiple vulnerabilitiesEPSS 0.4%CVE-2025-2766HIGH70mai A510 Use of Default Password Authentication Bypass VulnerabilityEPSS 0.4%CVE-2025-2921MEDIUMNetis WF-2404 passwd default passwordEPSS 0.3%CVE-2026-16503CRITICALVPS.org one-click Supabase template deployment instance contains multiple vulnerabilitiesEPSS 0.3%CVE-2026-82698MEDIUMsambitraj Student-Management-System aca.sql default passwordEPSS 0.3%CVE-2024-36440MEDIUMAn issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may recover the administEPSS 0.3%CVE-2026-54445MEDIUMVantage6: Set admin user and password from environment or configurationEPSS 0.3%CVE-2026-69657CRITICALXING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected deviEPSS 0.3%CVE-2025-1878LOWi-Drive i11/i12 WiFi default passwordEPSS 0.3%CVE-2025-43799MEDIUMLiferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA throuEPSS 0.3%