VYPR

CWE-1391

Use of Weak Credentials

ClassIncomplete

Description

The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.

Hierarchy (View 1000)

CVEs mapped to this weakness (58)

page 2 of 3
  • CVE-2024-42051HigJul 28, 2024
    risk 0.51cvss 7.8epss 0.00

    The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by replacing InstRegExp.reg.

  • CVE-2023-48257HigJan 10, 2024
    risk 0.51cvss 7.8epss 0.01

    The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on the device. The vulnerability can be exploited directly by authenticated users, via crafted HTTP requests, or…

  • CVE-2023-0635HigJun 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021,…

  • CVE-2026-49852HigJul 17, 2026
    risk 0.50cvss epss 0.00

    joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-forged HMAC-signed tokens when the caller-supplied verification key is the empty string or None,…

  • CVE-2025-6523HigJul 22, 2025
    risk 0.50cvss 7.7epss 0.00

    Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following…

  • CVE-2025-2229HigMar 13, 2025
    risk 0.50cvss 7.7epss 0.00

    A token is created using the username, current date/time, and a fixed AES-128 encryption key, which is the same across all installations.

  • CVE-2024-7558HigOct 2, 2024
    risk 0.50cvss 8.7epss 0.01

    JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the…

  • CVE-2024-32759HigJul 10, 2024
    risk 0.50cvss epss 0.00

    Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.

  • CVE-2026-22910HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.

  • CVE-2025-59460HigOct 27, 2025
    risk 0.49cvss 7.5epss 0.00

    The system is deployed in its default state, with configuration settings that do not comply with the latest best practices for restricting access. This increases the risk of unauthorised connections.

  • CVE-2025-35970HigAug 7, 2025
    risk 0.49cvss 7.5epss 0.00

    On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from the information available via SNMP. If the administrator password is not changed from the initial one, a remote attacker with SNMP access can log in to the…

  • CVE-2025-52364HigJul 9, 2025
    risk 0.49cvss 7.5epss 0.01

    Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service (telnetd) by default at boot via the initialization script /etc/init.d/eth.sh. This allows remote attackers to connect to the device s shell over the network, potentially without…

  • CVE-2024-52331HigJan 23, 2025
    risk 0.49cvss 7.5epss 0.00

    ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.

  • CVE-2024-45722HigDec 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses weak credential mechanism that could allow an attacker to easily calculate MQTT credentials.

  • CVE-2024-45272HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.

  • CVE-2022-3010HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.01

    The Priva TopControl Suite contains predictable credentials for the SSH service, based on the Serial number. Which makes it possible for an attacker to calculate the login credentials for the Priva TopControll suite.

  • CVE-2025-6737HigAug 25, 2025
    risk 0.47cvss 7.2epss 0.00

    Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenants. A malicious actor can obtain authentication material and access the gateway server with low-privilege permissions.

  • CVE-2024-43659HigJan 9, 2025
    risk 0.47cvss 7.2epss 0.01

    After gaining access to the firmware of a charging station, a file at can be accessed to obtain default credentials that are the same across all Iocharger AC model EV chargers. This issue affects Iocharger firmware for AC models before firmware version 25010801. …

  • CVE-2024-40892HigAug 12, 2024
    risk 0.46cvss 7.1epss 0.01

    A weak credential vulnerability exists in Firewalla Box Software versions before 1.979. This vulnerability allows a physically close attacker to use the license UUID for authentication and provision SSH credentials over the Bluetooth Low-Energy (BTLE) interface. Once an attacker…

  • CVE-2026-46623higJun 26, 2026
    risk 0.45cvss epss

    ## Summary **Description** An Unverified Password Change (CWE-620) and Use of Weak Credentials (CWE-1391) issue in OpenAM's OAuth2 authentication module silently rewrites a local user's password to the literal string of their username on OAuth2 re-login of an existing account.…