CWE-1188— Insecure Default Initialization of Resource
The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.— MITRE CWE catalog
362 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1188page 2 of 8
- CVE-2022-41648CRITICALCVSS 9.8EG 9.82022-10-28
The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machines. Authentication is not enabled by default for DNC communication. This vulnerability may…
- CVE-2021-3586CRITICALCVSS 9.8EG 9.82022-08-22
A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allowing access to all ports on these resources from any pod. The highest threat from this vul…
- CVE-2022-31806CRITICALCVSS 9.8EG 9.82022-06-24
In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the contr…
- CVE-2021-38759CRITICALCVSS 9.8EG 9.82021-12-07
Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges.
- CVE-2021-42109CRITICALCVSS 9.8EG 9.82021-10-08
VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.
- CVE-2021-35965CRITICALCVSS 9.8EG 9.82021-07-19
The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege without logging in.
- CVE-2021-35336CRITICALCVSS 9.8EG 9.82021-07-01
Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web Administrative Interface could allow an unauthenticated user to access a sensitive part of the system with a high privil…
- CVE-2021-28123CRITICALCVSS 9.8EG 9.82021-04-02
Undocumented Default Cryptographic Key Vulnerability in Cohesity DataPlatform version 6.3 prior 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. The ssh key can provide an attacker access to the linux system in the affected version.
- CVE-2020-4001CRITICALCVSS 9.8EG 9.82020-11-24
The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash attack.
- CVE-2020-27555CRITICALCVSS 9.8EG 9.82020-11-17
Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute arbitrary system commands as the root user.
- CVE-2020-26510CRITICALCVSS 9.8EG 9.82020-11-16
Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution.
- CVE-2020-10279CRITICALCVSS 9.8EG 9.82020-06-24
MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for robots. These insecurities include a way for users to escalate…
- CVE-2020-14011CRITICALCVSS 9.8EG 9.82020-06-15
Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked. This allows command execution via the Add New Package and Scheduled D…
- CVE-2020-11532CRITICALCVSS 9.8EG 9.82020-05-08
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of …
- CVE-2014-0234CRITICALCVSS 9.8EG 9.82020-02-12
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.s…
- CVE-2019-16272CRITICALCVSS 9.8EG 9.82020-01-06
On DTEN D5 and D7 before 1.3.4 devices, factory settings allows for firmware reflash and Android Debug Bridge (adb) enablement.
- CVE-2019-4621CRITICALCVSS 9.8EG 9.82019-12-09
IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain unauthorised access t…
- CVE-2019-16102CRITICALCVSS 9.8EG 9.82019-09-08
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has an SNMP service with a public value for rocommunity and trapcommunity.
- CVE-2019-14222CRITICALCVSS 9.8EG 9.82019-09-05
An issue was discovered in Alfresco Community Edition versions 6.0 and lower. An unauthenticated, remote attacker could authenticate to Alfresco's Solr Web Admin Interface. The vulnerability is due to the presence of a default private key …
- CVE-2019-7252CRITICALCVSS 9.8EG 9.82019-07-02
Linear eMerge E3-Series devices have Default Credentials.
- CVE-2019-5497CRITICALCVSS 9.8EG 9.82019-07-01
NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that could allow unauthorized arbitrary command execution.
- CVE-2019-7668CRITICALCVSS 9.8EG 9.82019-07-01
Prima Systems FlexAir devices have Default Credentials.
- CVE-2019-5367CRITICALCVSS 9.8EG 9.82019-06-05
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
- CVE-2019-1804CRITICALCVSS 9.8EG 9.82019-05-03
A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to connect to the affected system with the privileges o…
- CVE-2019-11618CRITICALCVSS 9.8EG 9.82019-04-30
doorGets 7.0 has a default administrator credential vulnerability. A remote attacker can use this vulnerability to gain administrator privileges for the creation and modification of articles via an H0XZlT44FcN1j9LTdFc5XRXhlF30UaGe1g3cZY6i1…
- CVE-2018-19275CRITICALCVSS 9.8EG 9.82019-04-02
The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote attackers to gain unauthorized access and execute arbitrary scripts with potential impacts to the …
- CVE-2019-5490CRITICALCVSS 9.8EG 9.82019-03-21
Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary command execution. Any platform listed in the advisory Imp…
- CVE-2019-3909CRITICALCVSS 9.8EG 9.82019-01-18
Premisys Identicard version 3.1.190 database uses default credentials. Users are unable to change the credentials without vendor intervention.
- CVE-2018-15350CRITICALCVSS 9.8EG 9.82018-08-17
Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileged access to the router.
- CVE-2018-10968CRITICALCVSS 9.8EG 9.82018-05-18
On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can use a default TELNET account to get unauthorized access to vulnerable devices, aka a backdoor access vulnerability.
- CVE-2018-8014CRITICALCVSS 9.8EG 9.82018-05-16
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the C…
- CVE-2018-10251CRITICALCVSS 9.8EG 9.82018-05-04
A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 could allow an unauthenticated remote attacker t…
- CVE-2018-3591CRITICALCVSS 9.8EG 9.82018-04-11
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD…
- CVE-2018-5770CRITICALCVSS 9.8EG 9.82018-03-20
An issue was discovered on Tenda AC15 devices. A remote, unauthenticated attacker can make a request to /goform/telnet, creating a telnetd service on the device. This service is password protected; however, several default accounts exist o…
- CVE-2018-0130CRITICALCVSS 9.8EG 9.82018-02-22
A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to gain administrative access to an affected system. The vulnerabil…
- CVE-2017-12739CRITICALCVSS 9.8EG 9.82017-11-15
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected devices could allow unauthenticated remo…
- CVE-2017-8021CRITICALCVSS 9.8EG 9.82017-10-03
EMC Elastic Cloud Storage (ECS) before 3.1 is affected by an undocumented account vulnerability that could potentially be leveraged by malicious users to compromise the affected system.
- CVE-2017-8218CRITICALCVSS 9.8EG 9.82017-04-25
vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n has a backdoor admin account with the 1234 password, a backdoor guest account with the guest password, and a backdoor test account with the te…
- CVE-2017-3834CRITICALCVSS 9.8EG 9.82017-04-06
A vulnerability in Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points running Cisco Mobility Express Software could allow an unauthenticated, remote attacker to take complete control of an affected device. The vulnerabil…
- CVE-2017-5178CRITICALCVSS 9.8EG 9.82017-03-08
An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonderware Intelligence Versions 2014R3 and prior. These versions contain a system account that is installed by default. The default system acco…
- CVE-2021-21505CRITICALCVSS 8.0EG 9.82021-05-06
Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit th…
- CVE-2022-48342CRITICALCVSS 5.2EG 9.82023-02-23
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
- CVE-2026-43581CRITICALCVSS 9.6EG 9.62026-05-06
OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.0. Attackers can access the DevTools protocol outside intended local sandbox bound…
- CVE-2026-66066CRITICALCVSS 9.5EG 9.52026-07-30
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to…
- CVE-2026-44670CRITICALCVSS 9.4EG 9.42026-05-14
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / database) names without any HTML escape, then a render template uses raw strings.ReplaceAll(tpl, "${avName}", nodeAvName)…
- CVE-2026-44588CRITICALCVSS 9.4EG 9.42026-05-14
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/block/popover.ts reads aria-label via getAttribute and passes it through decodeURIComponent before assigning to message…
- CVE-2026-24148CRITICALCVSS 9.4EG 9.42026-03-31
NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default. A successful exploit of this vulnerability might l…
- CVE-2025-69970CRITICALCVSS 9.3EG 9.32026-02-03
FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unaut…
- CVE-2025-59097CRITICALCVSS 9.3EG 9.32026-01-26
The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done in a graphical user interface on the dormakaba exos server. As soon as the save button is clicked in exos 9300, the wh…
- CVE-2025-59090CRITICALCVSS 9.3EG 9.32026-01-26
On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sending requests. Therefore, network access to the exos server allows e.g. the creation of arbitrary access log events as …
Map vulnerabilities like CWE-1188 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1188 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →