VYPR

CWE-1391

Use of Weak Credentials

ClassIncomplete

Description

The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.

Hierarchy (View 1000)

CVEs mapped to this weakness (35)

page 1 of 2
  • CVE-2024-51978CriJun 25, 2025
    risk 0.69cvss 9.8epss 0.24

    An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request,…

  • CVE-2026-39920CriApr 24, 2026
    risk 0.64cvss 9.8epss 0.01

    BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to…

  • CVE-2026-22886CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.00

    OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login,…

  • CVE-2025-30519CriSep 18, 2025
    risk 0.64cvss 9.8epss 0.00

    Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standard administrative means. An attacker with network access to the device can gain administrative access to the system.

  • CVE-2025-6077CriAug 2, 2025
    risk 0.64cvss 9.8epss 0.01

    Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and password for the administrator account across all versions.

  • CVE-2024-43698CriOct 22, 2024
    risk 0.64cvss 9.8epss 0.00

    Kieback & Peter's DDC4000 series uses weak credentials, which may allow an unauthenticated attacker to get full admin rights on the system.

  • CVE-2026-8076CriMay 8, 2026
    risk 0.60cvss epss 0.00

    Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentication. The system supports the use of PIN-based credentials, maintaining compatibility with POS software integrations deployed…

  • CVE-2025-59103CriJan 26, 2026
    risk 0.60cvss epss 0.00

    The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revisions. In this new hardware revision it was noticed that an SSH service is exposed on port 22. By analyzing the firmware of the devices, it was noticed that…

  • CVE-2025-53558HigJul 31, 2025
    risk 0.59cvss 8.8epss 0.01

    ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected devices.

  • CVE-2026-35089HigMay 27, 2026
    risk 0.57cvss epss 0.01

    In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can be obtained without authentication. An unauthenticated attacker can deduce the secure key and obtain admin credentials. This issue was fixed in…

  • CVE-2024-29071HigMar 25, 2024
    risk 0.57cvss 8.8epss 0.00

    HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings.

  • CVE-2024-5634HigJul 9, 2024
    risk 0.56cvss epss 0.00

    Longse model LBH30FE200W cameras, as well as products based on this device, make use of telnet passwords which follow a specific pattern. Once the pattern is known, brute-forcing the password becomes relatively easy.  Additionally, every camera with the same firmware version…

  • CVE-2026-23853HigApr 17, 2026
    risk 0.55cvss 8.4epss 0.00

    Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a use of weak credentials vulnerability. An…

  • CVE-2026-44351CriMay 13, 2026
    risk 0.52cvss 9.1epss 0.00

    fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-resolver flow allows any unauthenticated attacker to forge arbitrary JWTs that are accepted as authentic. When the application's key…

  • CVE-2025-2229HigMar 13, 2025
    risk 0.50cvss 7.7epss 0.00

    A token is created using the username, current date/time, and a fixed AES-128 encryption key, which is the same across all installations.

  • CVE-2024-32759HigJul 10, 2024
    risk 0.50cvss epss 0.00

    Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.

  • CVE-2025-35970HigAug 7, 2025
    risk 0.49cvss 7.5epss 0.00

    On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from the information available via SNMP. If the administrator password is not changed from the initial one, a remote attacker with SNMP access can log in to the…

  • CVE-2025-6737HigAug 25, 2025
    risk 0.47cvss 7.2epss 0.00

    Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenants. A malicious actor can obtain authentication material and access the gateway server with low-privilege permissions.

  • CVE-2024-43659HigJan 9, 2025
    risk 0.47cvss 7.2epss 0.01

    After gaining access to the firmware of a charging station, a file at can be accessed to obtain default credentials that are the same across all Iocharger AC model EV chargers. This issue affects Iocharger firmware for AC models before firmware version 25010801. …

  • CVE-2024-40892HigAug 12, 2024
    risk 0.47cvss 7.1epss 0.01

    A weak credential vulnerability exists in Firewalla Box Software versions before 1.979. This vulnerability allows a physically close attacker to use the license UUID for authentication and provision SSH credentials over the Bluetooth Low-Energy (BTLE) interface. Once an attacker…