VYPR

CWE-1392

Use of Default Credentials

BaseIncomplete

Description

The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

It is common practice for products to be designed to use default keys, passwords, or other mechanisms for authentication. The rationale is to simplify the manufacturing process or the system administrator's task of installation and deployment into an enterprise. However, if admins do not change the defaults, it is easier for attackers to bypass authentication quickly across multiple organizations.

Hierarchy (View 1000)

CVEs mapped to this weakness (109)

page 2 of 6
  • CVE-2023-49621CriJan 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses default credential with admin privileges. An attacker could use the credentials to gain complete control of the affected…

  • CVE-2023-30801CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.01

    All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials…

  • CVE-2023-30603CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Hitron Technologies CODA-5310 Telnet function with the default account and password, and there is no warning or prompt to ask users to change the default password and account. An unauthenticated remote attackers can exploit this vulnerability to obtain the administrator’s…

  • CVE-2026-7428CriMay 12, 2026
    risk 0.60cvss epss 0.00

    Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could have been exploited by a remote attacker to gain full administrative access to the database. …

  • CVE-2025-59108CriJan 26, 2026
    risk 0.60cvss epss 0.00

    By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the password was not enforced.

  • CVE-2021-47707CriDec 9, 2025
    risk 0.60cvss epss 0.00

    COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclose RTSP stream. Attackers can exploit this by sending a POST request with the 'passkey' parameter set to '1234', allowing them to access the web control panel.

  • CVE-2025-12592CriNov 19, 2025
    risk 0.60cvss epss 0.00

    Legacy Vivotek Device firmware uses default credetials for the root and user login accounts.

  • CVE-2024-4007HigJul 1, 2024
    risk 0.60cvss 8.8epss 0.02

    Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.

  • CVE-2023-27573CriMar 11, 2026
    risk 0.59cvss 9.0epss 0.00

    netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SUPERUSER_API_TOKEN). In practice on the public Internet, almost all users changed the password but only…

  • CVE-2025-12218CriOct 25, 2025
    risk 0.59cvss 9.1epss 0.00

    Weak Default Credentials.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

  • CVE-2025-12217CriOct 25, 2025
    risk 0.59cvss 9.1epss 0.00

    SNMP Default Community String (public).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

  • CVE-2025-51535CriAug 4, 2025
    risk 0.59cvss 9.1epss 0.00

    Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.

  • CVE-2025-29629CriJul 25, 2025
    risk 0.59cvss 9.1epss 0.00

    Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.

  • CVE-2026-68503CriJul 30, 2026
    risk 0.57cvss 9.8epss 0.00

    LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP Basic authentication, allowing…

  • CVE-2026-9844HigJun 2, 2026
    risk 0.57cvss epss 0.00

    Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Passwords. This issue affects navify Digital Pathology: from 2.0.0 before 2.4.1.

  • CVE-2026-42072CriMay 8, 2026
    risk 0.57cvss 9.8epss 0.00

    Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. Prior to version 1.0.42-hotfix, the --address CLI flag (and NORNICDB_ADDRESS / server.host config key) is plumbed through to the HTTP server correctly but…

  • CVE-2025-7740HigJan 28, 2026
    risk 0.57cvss epss 0.00

    Default credentials vulnerability exists in SuprOS product. If exploited, this could allow an authenticated local attacker to use an admin account created during product deployment.

  • CVE-2026-22273HigJan 23, 2026
    risk 0.57cvss 8.8epss 0.00

    Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default Credentials vulnerability in the OS. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of…

  • CVE-2025-6529HigJun 23, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in 70mai M300 up to 20250611 and classified as critical. Affected by this issue is some unknown functionality of the component Telnet Service. The manipulation leads to use of default credentials. The attack needs to be initiated within the local…

  • CVE-2024-28093HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.00

    The TELNET service of AdTran NetVanta 3120 18.01.01.00.E devices is enabled by default, and has default credentials for a root-level account.