VYPR

CWE-1391

Use of Weak Credentials

ClassIncomplete

Description

The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.

Hierarchy (View 1000)

CVEs mapped to this weakness (58)

page 1 of 3
  • CVE-2024-51978CriJun 25, 2025
    risk 0.69cvss 9.8epss 0.24

    An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request,…

  • CVE-2026-39920CriApr 24, 2026
    risk 0.64cvss 9.8epss 0.01

    BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to…

  • CVE-2025-67114CriMar 19, 2026
    risk 0.64cvss 9.8epss 0.01

    Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers to derive valid administrative/root credentials from the device's MAC address, enabling…

  • CVE-2026-22886CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.00

    OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login,…

  • CVE-2025-30519CriSep 18, 2025
    risk 0.64cvss 9.8epss 0.00

    Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standard administrative means. An attacker with network access to the device can gain administrative access to the system.

  • CVE-2025-6077CriAug 2, 2025
    risk 0.64cvss 9.8epss 0.01

    Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and password for the administrator account across all versions.

  • CVE-2024-12728CriDec 19, 2024
    risk 0.64cvss 9.8epss 0.01

    A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3).

  • CVE-2024-43698CriOct 22, 2024
    risk 0.64cvss 9.8epss 0.00

    Kieback & Peter's DDC4000 series uses weak credentials, which may allow an unauthenticated attacker to get full admin rights on the system.

  • CVE-2026-8076CriMay 8, 2026
    risk 0.60cvss epss 0.00

    Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentication. The system supports the use of PIN-based credentials, maintaining compatibility with POS software integrations deployed…

  • CVE-2025-59103CriJan 26, 2026
    risk 0.60cvss epss 0.00

    The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revisions. In this new hardware revision it was noticed that an SSH service is exposed on port 22. By analyzing the firmware of the devices, it was noticed that…

  • CVE-2026-35089HigMay 27, 2026
    risk 0.57cvss epss 0.01

    In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can be obtained without authentication. An unauthenticated attacker can deduce the secure key and obtain admin credentials. This issue was fixed in…

  • CVE-2025-53558HigJul 31, 2025
    risk 0.57cvss 8.8epss 0.01

    ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected devices.

  • CVE-2024-28066HigApr 8, 2024
    risk 0.57cvss 8.8epss 0.00

    In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).

  • CVE-2024-29071HigMar 25, 2024
    risk 0.57cvss 8.8epss 0.00

    HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings.

  • CVE-2023-37266CriJul 17, 2023
    risk 0.57cvss 9.8epss 0.07

    CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. This problem was addressed by improving the validation of JWTs…

  • CVE-2024-5634HigJul 9, 2024
    risk 0.56cvss epss 0.00

    Longse model LBH30FE200W cameras, as well as products based on this device, make use of telnet passwords which follow a specific pattern. Once the pattern is known, brute-forcing the password becomes relatively easy.  Additionally, every camera with the same firmware version…

  • CVE-2026-23853HigApr 17, 2026
    risk 0.55cvss 8.4epss 0.00

    Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a use of weak credentials vulnerability. An…

  • CVE-2023-31240HigMay 22, 2023
    risk 0.54cvss 8.3epss 0.01

    Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely. OvrC cloud contains a hidden superuser account accessible through hard-coded credentials.

  • CVE-2026-45363CriJul 14, 2026
    risk 0.52cvss 9.1epss 0.00

    ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', payload) returns a valid digest under an empty…

  • CVE-2026-44351CriMay 13, 2026
    risk 0.52cvss 9.1epss 0.00

    fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-resolver flow allows any unauthenticated attacker to forge arbitrary JWTs that are accepted as authentic. When the application's key…