CWE-1188— Insecure Default Initialization of Resource
The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.— MITRE CWE catalog
362 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1188page 8 of 8
- CVE-2020-11917MEDIUMCVSS 4.3EG 4.32024-11-07
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. It uses a default SSID value, which makes it easier for remote attackers to discover the physical locations of many Siime Eye devices, violating the privacy of users who do…
- CVE-2026-0134MEDIUMCVSS 4.0EG 4.02026-06-16
In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User int…
- CVE-2024-30124MEDIUMCVSS 4.0EG 4.02024-10-23
HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.
- CVE-2026-73596LOWCVSS 3.8EG 3.82026-09-29
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with remote access could potentially exploit this v…
- CVE-2024-56433LOWCVSS 3.6EG 3.62024-12-26
shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered net…
- CVE-2022-20342LOWCVSS 3.3EG 3.32022-08-12
In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e…
- CVE-2020-26930LOWCVSS 3.3EG 3.32020-10-09
NETGEAR EX7700 devices before 1.0.0.210 are affected by incorrect configuration of security settings.
- CVE-2026-55708LOWCVSS 3.1EG 3.12026-07-22
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no loca…
- CVE-2023-3485LOWCVSS 3.0EG 3.02023-06-30
Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker to craft a task token with access to a namespace other than the one specified in the request. Creation of this task token must be done…
- CVE-2025-27443LOWCVSS 2.8EG 2.82025-04-08
Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access.
- CVE-2024-34063LOWCVSS 2.5EG 2.52024-05-03
vodozemac is an implementation of Olm and Megolm in pure Rust. Versions 0.5.0 and 0.5.1 of vodozemac have degraded secret zeroization capabilities, due to changes in third-party cryptographic dependencies (the Dalek crates), which moved se…
- CVE-2024-51758LOWCVSS 2.3EG 2.32024-11-07
Filament is a collection of full-stack components for accelerated Laravel development. All Filament features that interact with storage use the `default_filesystem_disk` config option. This allows the user to easily swap their storage driv…
Map vulnerabilities like CWE-1188 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1188 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →