VYPR

CWE-1393

Use of Default Password

BaseIncomplete

Description

The product uses default passwords for potentially critical functionality.

It is common practice for products to be designed to use default passwords for authentication. The rationale is to simplify the manufacturing process or the system administrator's task of installation and deployment into an enterprise. However, if admins do not change the defaults, then it makes it easier for attackers to quickly bypass authentication across multiple organizations. There are many lists of default passwords and default-password scanning tools that are easily available from the World Wide Web.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (46)

page 2 of 3
  • CVE-2024-29021CriApr 18, 2024
    risk 0.60cvss 9.0epss 0.20

    Judge0 is an open-source online code execution system. The default configuration of Judge0 leaves the service vulnerable to a sandbox escape via Server Side Request Forgery (SSRF). This allows an attacker with sufficient access to the Judge0 API to obtain unsandboxed code…

  • CVE-2026-16503CriJul 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW…

  • CVE-2025-8077CriSep 17, 2025
    risk 0.57cvss 9.8epss 0.01

    A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default password for the built-in `admin` account. If this password is not changed immediately after deployment, any workload with network access within the cluster could…

  • CVE-2025-2766HigJun 6, 2025
    risk 0.57cvss 8.8epss 0.00

    70mai A510 Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of 70mai A510. Authentication is not required to exploit this vulnerability. The specific flaw exists…

  • CVE-2024-49559HigMar 17, 2025
    risk 0.57cvss 8.8epss 0.00

    Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

  • CVE-2026-4404CriMar 23, 2026
    risk 0.54cvss 9.4epss 0.01

    Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

  • CVE-2023-28094HigJun 22, 2023
    risk 0.53cvss 8.1epss 0.01

    Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.

  • CVE-2026-19851HigAug 25, 2026
    risk 0.50cvss 7.7epss 0.00

    A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to gain access to user accounts created during XML import.

  • CVE-2023-43042HigDec 14, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.3 products use default passwords for a privileged user. IBM X-Force ID: 266874.

  • CVE-2024-13966HigMay 27, 2025
    risk 0.47cvss 7.3epss 0.00

    ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should change their passwords (located under the Attendance Settings tab as "Self-Password").

  • CVE-2024-43659HigJan 9, 2025
    risk 0.47cvss 7.2epss 0.01

    After gaining access to the firmware of a charging station, a file at can be accessed to obtain default credentials that are the same across all Iocharger AC model EV chargers. This issue affects Iocharger firmware for AC models before firmware version 25010801. …

  • CVE-2026-54445MedJun 17, 2026
    risk 0.45cvss —epss 0.00

    vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not ideal because attackers know that almost all vantage6 servers have a user with username `root` that…

  • CVE-2025-14917MedMar 25, 2026
    risk 0.44cvss 6.7epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings.

  • CVE-2024-36440MedAug 22, 2024
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may recover the administrative device password via password-cracking methods, because unsalted MD5 is used.

  • CVE-2025-43799MedSep 15, 2025
    risk 0.42cvss 6.5epss 0.00

    Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has changed their…

  • CVE-2025-2921MedMar 28, 2025
    risk 0.42cvss 6.4epss 0.00

    A vulnerability classified as critical has been found in Netis WF-2404 1.1.124EN. Affected is an unknown function of the file /etc/passwd. The manipulation with the input Realtek leads to use of default password. It is possible to launch the attack on the physical device. The…

  • CVE-2026-2635HigFeb 20, 2026
    risk 0.41cvss 7.3epss 0.01

    MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2025-2347MedMar 16, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in IROAD Dash Cam FX2 up to 20250308 and classified as problematic. This issue affects some unknown processing of the component Device Registration. The manipulation of the argument Password with the input qwertyuiop leads to use of default password.…

  • CVE-2025-43021MedJul 22, 2025
    risk 0.37cvss 5.7epss 0.00

    A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the use and retrieval of the default password. HP has addressed the issue in the latest software update.

  • CVE-2024-48987MedOct 11, 2024
    risk 0.36cvss 6.6epss 0.01

    Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.