VYPR

CWE-1188

Initialization of a Resource with an Insecure Default

BaseIncomplete

Description

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (330)

page 2 of 17
  • CVE-2025-54127CriJul 21, 2025
    risk 0.64cvss 9.8epss 0.00

    HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of HAXcms uses an insecure default configuration designed for local development. The default configuration does not perform…

  • CVE-2025-24288CriJun 19, 2025
    risk 0.64cvss 9.8epss 0.00

    The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes ssh and postgres to the…

  • CVE-2025-41438CriMay 30, 2025
    risk 0.64cvss 9.8epss 0.01

    The CS5000 Fire Panel is vulnerable due to a default account that exists on the panel. Even though it is possible to change this by SSHing into the device, it has remained unchanged on every installed system observed. This account is not root but holds high-level permissions…

  • CVE-2025-1863CriApr 18, 2025
    risk 0.64cvss 9.8epss 0.01

    Insecure default settings have been found in recorder products provided by Yokogawa Electric Corporation. The default setting of the authentication function is disabled on the affected products. Therefore, when connected to a network with default settings, anyone can access all…

  • CVE-2025-1960CriMar 12, 2025
    risk 0.64cvss 9.8epss 0.01

    CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an attacker to execute unauthorized commands when a system’s default password credentials have not been changed on first use. The default username is not displayed correctly…

  • CVE-2024-50390CriMar 7, 2025
    risk 0.64cvss 9.8epss 0.01

    A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later

  • CVE-2024-28815CriMar 27, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the BluStar component of Mitel InAttend 2.6 SP4 through 2.7 and CMG 8.5 SP4 through 8.6 could allow access to sensitive information, changes to the system configuration, or execution of arbitrary commands within the context of the system.

  • CVE-2022-41648CriOct 28, 2022
    risk 0.64cvss 9.8epss 0.01

    The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machines. Authentication is not enabled by default for DNC communication. This vulnerability may allow an attacker to deny service on…

  • CVE-2021-3586CriAug 22, 2022
    risk 0.64cvss 9.8epss 0.01

    A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allowing access to all ports on these resources from any pod. The highest threat from this vulnerability is to data confidentiality…

  • CVE-2022-31806CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.01

    In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.

  • CVE-2021-42109CriOct 8, 2021
    risk 0.64cvss 9.8epss 0.02

    VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.

  • CVE-2021-35965CriJul 19, 2021
    risk 0.64cvss 9.8epss 0.02

    The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege without logging in.

  • CVE-2021-28123CriApr 2, 2021
    risk 0.64cvss 9.8epss 0.01

    Undocumented Default Cryptographic Key Vulnerability in Cohesity DataPlatform version 6.3 prior 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. The ssh key can provide an attacker access to the linux system in the affected version.

  • CVE-2020-4001CriNov 24, 2020
    risk 0.64cvss 9.8epss 0.03

    The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash attack.

  • CVE-2020-27555CriNov 17, 2020
    risk 0.64cvss 9.8epss 0.03

    Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute arbitrary system commands as the root user.

  • CVE-2020-26510CriNov 16, 2020
    risk 0.64cvss 9.8epss 0.02

    Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution.

  • CVE-2020-10279CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.01

    MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for robots. These insecurities include a way for users to escalate their access beyond what they were…

  • CVE-2014-0234CriFeb 12, 2020
    risk 0.64cvss 9.8epss 0.04

    The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before…

  • CVE-2019-16272CriJan 6, 2020
    risk 0.64cvss 9.8epss 0.01

    On DTEN D5 and D7 before 1.3.4 devices, factory settings allows for firmware reflash and Android Debug Bridge (adb) enablement.

  • CVE-2019-4621CriDec 9, 2019
    risk 0.64cvss 9.8epss 0.02

    IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain unauthorised access to the BMC. IBM X-Force ID: 168883.