Falhas do tipo CWE-1392

116 resultados

Uso de Credenciais Padrão

A aplicação ou dispositivo é entregue com credenciais (usuário/senha, chaves de API, tokens) pré-configuradas que são públicas, documentadas ou fáceis de adivinhar. Um atacante que conhece essas credenciais padrão consegue acessar o sistema sem qualquer autenticação legítima, comprometendo confidencialidade, integridade e disponibilidade.

Exemplo

Um roteador, câmera IP ou painel administrativo de software vem com login 'admin/admin' ou 'root/12345'. Se o usuário não altera essas credenciais na primeira configuração, qualquer pessoa na rede (ou pela internet, se exposta) consegue entrar e modificar configurações críticas ou roubar dados.

Como mitigar

Force a alteração de credenciais padrão na primeira inicialização, bloqueando acesso até que o usuário defina uma senha forte única. Nunca distribua aplicações ou dispositivos com credenciais fixas codificadas; se necessário usar padrões temporários, expire-as em horas e registre tentativas de acesso com credenciais padrão.

CVE-2025-54303CRITICALThe Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API.EPSS 0.4%CVE-2026-31837HIGHIstio JWKS resolver to prevent private key material from being exposed when JWKS fetch fails.EPSS 0.4%CVE-2020-36915HIGHAdtec Digital SignEdje Digital Signage Player v2.08.28 Default CredentialsEPSS 0.4%CVE-2021-47707CRITICALCOMMAX CVD-Axx DVR Weak Default Credentials Stream DisclosureEPSS 0.4%CVE-2026-86464CRITICALIn the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deploEPSS 0.4%CVE-2025-1711MEDIUMCVE-2025-1711EPSS 0.3%CVE-2026-22273HIGHDell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default Credentials vulnerabiEPSS 0.3%CVE-2024-12013HIGHA CWE-1392 “Use of Default Credentials” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The device exposeEPSS 0.3%CVE-2025-55051CRITICALCWE-1392: Use of Default CredentialsEPSS 0.3%CVE-2023-40704MEDIUMPhilips Vue PACS Use of Default CredentialsEPSS 0.3%CVE-2025-35114HIGHAgiloft local privilege escalation via default credentialsEPSS 0.3%CVE-2025-12592CRITICALUse of default login credentials in Legacy Vivotek DevicesEPSS 0.3%CVE-2025-54137HIGHNodeJS version of the HAX CMS application is distributed with Default SecretsEPSS 0.3%CVE-2024-30210HIGHIOSIX IO-1020 Micro ELD Use of Default CredentialsEPSS 0.3%CVE-2026-90451HIGHAn example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled EPSS 0.3%CVE-2025-22460HIGHDefault credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privilEPSS 0.3%CVE-2026-90940MEDIUMnovel-plus through 5.3.3 Default Cache Management Password in the Front PortalEPSS 0.3%CVE-2024-46899HIGHAuthentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVFEPSS 0.3%CVE-2024-45068HIGHAuthentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVAEPSS 0.3%CVE-2026-76155CRITICALDatiphy Data Management Center - Use of Default CredentialsEPSS 0.3%