CWE-1392
Use of Default Credentials
Description
The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.
Hierarchy (View 1000)
CVEs mapped to this weakness (109)
page 1 of 6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-55051 | — | Cri | 0.65 | 10.0 | 0.00 | Sep 9, 2025 | CWE-1392: Use of Default Credentials | |
| CVE-2023-3703 | Cri | 0.65 | 10.0 | 0.01 | Sep 3, 2023 | Proscend Advice ICR Series routers FW version 1.76 - CWE-1392: Use of Default Credentials | ||
| CVE-2026-45039 | Cri | 0.64 | 9.8 | 0.00 | May 28, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-SHA256 signature using a shared secret. The function that produces this secret, get_shared_secret() in… | ||
| CVE-2026-44159 | Cri | 0.64 | 9.8 | 0.00 | May 19, 2026 | Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment. TID-L has not been distributed since December 2020, and has not been supported since 2021. | ||
| CVE-2026-22886 | Cri | 0.64 | 9.8 | 0.00 | Mar 3, 2026 | OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login,… | ||
| CVE-2026-27751 | Cri | 0.64 | 9.8 | 0.00 | Feb 27, 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attackers can authenticate using the hardcoded default credentials without password… | ||
| CVE-2026-26341 | Cri | 0.64 | 9.8 | 0.03 | Feb 24, 2026 | Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default… | ||
| CVE-2026-26366 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2026 | eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Unauthenticated attackers can use these default credentials to gain… | ||
| CVE-2022-50803 | Cri | 0.64 | 9.8 | 0.00 | Dec 30, 2025 | JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the device with administrative privileges. | ||
| CVE-2025-54303 | Cri | 0.64 | 9.8 | 0.00 | Dec 4, 2025 | The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The ionadmin user account can be used to authenticate to default deployments with the password ionadmin. The user guide recommends… | ||
| CVE-2025-34516 | Cri | 0.64 | 9.8 | 0.01 | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to… | ||
| CVE-2025-10542 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2025 | iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s connection dialog. If the administrator does not change these defaults, a remote attacker can authenticate to the EAM server and gain full control over… | ||
| CVE-2025-35042 | Cri | 0.64 | 9.8 | 0.00 | Sep 22, 2025 | Airship AI Acropolis includes a default administrative account that uses the same credentials on every installation. Instances of Airship AI that do not change this account password are vulnerable to a remote attacker logging in and gaining the privileges of this account. Fixed… | ||
| CVE-2025-35452 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2025 | PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface. | ||
| CVE-2025-8731 | Cri | 0.64 | 9.8 | 0.01 | Aug 8, 2025 | A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown part of the component SSH Service. The manipulation leads to use of default credentials. It is possible to initiate the attack remotely. The exploit has been… | ||
| CVE-2025-51536 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2025 | Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password. | ||
| CVE-2025-30139 | Cri | 0.64 | 9.8 | 0.00 | Mar 18, 2025 | An issue was discovered on G-Net Dashcam BB GONX devices. Default credentials for SSID cannot be changed. It broadcasts a fixed SSID with default credentials that cannot be changed. This allows any nearby attacker to connect to the dashcam's network without restriction. Once… | ||
| CVE-2024-12286 | Cri | 0.64 | 9.8 | 0.00 | Dec 10, 2024 | MOBATIME Network Master Clock - DTS 4801 allows attackers to use SSH to gain initial access using default credentials. | ||
| CVE-2024-7746 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2024 | Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the Traccar solution that should otherwise be protected by the authentication… | ||
| CVE-2024-29844 | Cri | 0.64 | 9.8 | 0.01 | Apr 15, 2024 | Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the password. There is no warning or… |
- risk 0.65cvss 10.0epss 0.00
CWE-1392: Use of Default Credentials
- risk 0.65cvss 10.0epss 0.01
Proscend Advice ICR Series routers FW version 1.76 - CWE-1392: Use of Default Credentials
- risk 0.64cvss 9.8epss 0.00
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-SHA256 signature using a shared secret. The function that produces this secret, get_shared_secret() in…
- risk 0.64cvss 9.8epss 0.00
Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment. TID-L has not been distributed since December 2020, and has not been supported since 2021.
- risk 0.64cvss 9.8epss 0.00
OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login,…
- risk 0.64cvss 9.8epss 0.00
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attackers can authenticate using the hardcoded default credentials without password…
- risk 0.64cvss 9.8epss 0.03
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default…
- risk 0.64cvss 9.8epss 0.01
eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Unauthenticated attackers can use these default credentials to gain…
- risk 0.64cvss 9.8epss 0.00
JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the device with administrative privileges.
- risk 0.64cvss 9.8epss 0.00
The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The ionadmin user account can be used to authenticate to default deployments with the password ionadmin. The user guide recommends…
- risk 0.64cvss 9.8epss 0.01
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to…
- risk 0.64cvss 9.8epss 0.01
iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s connection dialog. If the administrator does not change these defaults, a remote attacker can authenticate to the EAM server and gain full control over…
- risk 0.64cvss 9.8epss 0.00
Airship AI Acropolis includes a default administrative account that uses the same credentials on every installation. Instances of Airship AI that do not change this account password are vulnerable to a remote attacker logging in and gaining the privileges of this account. Fixed…
- risk 0.64cvss 9.8epss 0.01
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.
- risk 0.64cvss 9.8epss 0.01
A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown part of the component SSH Service. The manipulation leads to use of default credentials. It is possible to initiate the attack remotely. The exploit has been…
- risk 0.64cvss 9.8epss 0.01
Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.
- risk 0.64cvss 9.8epss 0.00
An issue was discovered on G-Net Dashcam BB GONX devices. Default credentials for SSID cannot be changed. It broadcasts a fixed SSID with default credentials that cannot be changed. This allows any nearby attacker to connect to the dashcam's network without restriction. Once…
- risk 0.64cvss 9.8epss 0.00
MOBATIME Network Master Clock - DTS 4801 allows attackers to use SSH to gain initial access using default credentials.
- risk 0.64cvss 9.8epss 0.01
Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the Traccar solution that should otherwise be protected by the authentication…
- risk 0.64cvss 9.8epss 0.01
Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the password. There is no warning or…