CWE-1392— Use of Default Credentials
The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.— MITRE CWE catalog
121 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1392page 1 of 3
- CVE-2026-100103CRITICALCVSS 10.0EG 10.02026-10-05
Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially …
- CVE-2025-55051CRITICALCVSS 10.0EG 10.02025-09-09
CWE-1392: Use of Default Credentials
- CVE-2023-3703CRITICALCVSS 10.0EG 10.02023-09-03
Proscend Advice ICR Series routers FW version 1.76 - CWE-1392: Use of Default Credentials
- CVE-2026-108263CRITICALCVSS 9.9EG 9.92026-10-09
Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/…
- CVE-2026-86464CRITICALCVSS 9.9EG 9.92026-09-08
In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. …
- CVE-2026-46386CRITICALCVSS 9.9EG 9.92026-06-26
OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :mar…
- CVE-2026-90924CRITICALCVSS 9.8EG 9.82026-09-28
Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Try Common or Default Usernames and Passwords. This issue affects Logsign SIEM: from 6.4.101 before 6.4.11…
- CVE-2026-78573CRITICALCVSS 9.8EG 9.82026-09-10
IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.
- CVE-2026-68503CRITICALCVSS 9.8EG 9.82026-07-30
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.…
- CVE-2026-41939CRITICALCVSS 9.8EG 9.82026-07-29
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials…
- CVE-2026-3144CRITICALCVSS 9.8EG 9.82026-07-08
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
- CVE-2026-58466CRITICALCVSS 9.8EG 9.82026-07-02
AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly known default credentials seeded at startup via add_default_u…
- CVE-2026-58453CRITICALCVSS 9.8EG 9.82026-07-01
JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized access by using the default admin username with an empty passwo…
- CVE-2026-45039CRITICALCVSS 9.8EG 9.82026-05-28
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-SHA256 signature using a shared secret. The function that produces this secret, get_shared…
- CVE-2026-44159CRITICALCVSS 9.8EG 9.82026-05-19
Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment. TID-L has not been distributed since December 2020, and has not been supported since 2021.
- CVE-2026-42072CRITICALCVSS 9.8EG 9.82026-05-08
Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. Prior to version 1.0.42-hotfix, the --address CLI flag (and NORNICDB_ADDRESS / server.host config key) is plumbed …
- CVE-2023-27573CRITICALCVSS 9.8EG 9.82026-03-11
netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SUPERUSER_API_TOKEN). In practice on the public Internet, almost all …
- CVE-2026-22886CRITICALCVSS 9.8EG 9.82026-03-03
OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first u…
- CVE-2026-27751CRITICALCVSS 9.8EG 9.82026-02-27
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attackers can authenticate using the hardcoded…
- CVE-2026-26341CRITICALCVSS 9.8EG 9.82026-02-24
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface ca…
- CVE-2026-26366CRITICALCVSS 9.8EG 9.82026-02-15
eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Unauthenticated attackers can use these d…
- CVE-2022-50803CRITICALCVSS 9.8EG 9.82025-12-30
JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the device with administrative privileges.
- CVE-2025-54303CRITICALCVSS 9.8EG 9.82025-12-04
The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The ionadmin user account can be used to authenticate to default deployments with the password ion…
- CVE-2025-11943CRITICALCVSS 9.8EG 9.82025-10-19
A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality of the component HTTP Web Server. The manipulation leads to use of default credentials. The attack can be initiated rem…
- CVE-2025-34516CRITICALCVSS 9.8EG 9.82025-10-16
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommend…
- CVE-2025-10542CRITICALCVSS 9.8EG 9.82025-09-25
iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s connection dialog. If the administrator does not change these defaults, a remote attacker can authenticate to the EA…
- CVE-2025-35042CRITICALCVSS 9.8EG 9.82025-09-22
Airship AI Acropolis includes a default administrative account that uses the same credentials on every installation. Instances of Airship AI that do not change this account password are vulnerable to a remote attacker logging in and gainin…
- CVE-2025-35452CRITICALCVSS 9.8EG 9.82025-09-05
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.
- CVE-2025-8731CRITICALCVSS 9.8EG 9.82025-08-08
A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown part of the component SSH Service. The manipulation leads to use of default credentials. It is possible to initiate the at…
- CVE-2025-51536CRITICALCVSS 9.8EG 9.82025-08-04
Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.
- CVE-2025-30139CRITICALCVSS 9.8EG 9.82025-03-18
An issue was discovered on G-Net Dashcam BB GONX devices. Default credentials for SSID cannot be changed. It broadcasts a fixed SSID with default credentials that cannot be changed. This allows any nearby attacker to connect to the dashcam…
- CVE-2024-12286CRITICALCVSS 9.8EG 9.82024-12-10
MOBATIME Network Master Clock - DTS 4801 allows attackers to use SSH to gain initial access using default credentials.
- CVE-2024-7746CRITICALCVSS 9.8EG 9.82024-08-13
Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the Traccar solution that should otherwi…
- CVE-2024-29844CRITICALCVSS 9.8EG 9.82024-04-15
Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change…
- CVE-2023-49621CRITICALCVSS 9.8EG 9.82024-01-09
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses default credential with admin privileges. An attacker could use the credentials to …
- CVE-2023-30801CRITICALCVSS 9.8EG 9.82023-10-10
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote at…
- CVE-2023-30603CRITICALCVSS 9.8EG 9.82023-06-02
Hitron Technologies CODA-5310 Telnet function with the default account and password, and there is no warning or prompt to ask users to change the default password and account. An unauthenticated remote attackers can exploit this vulnerabil…
- CVE-2026-76155CRITICALCVSS 9.3EG 9.32026-08-21
Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials.
- CVE-2021-47707CRITICALCVSS 9.3EG 9.32025-12-09
COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclose RTSP stream. Attackers can exploit this by sending a POST request with the 'passkey' parameter set to '1234', allowin…
- CVE-2025-12592CRITICALCVSS 9.3EG 9.32025-11-19
Legacy Vivotek Device firmware uses default credetials for the root and user login accounts.
- CVE-2025-10678CRITICALCVSS 9.3EG 9.32025-10-20
NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL. This issue affects instances installed using vendor's provided script. This issue may affect inst…
- CVE-2026-7428CRITICALCVSS 9.2EG 9.22026-05-12
Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could have been exploited by a remote attacker to gain full…
- CVE-2025-59108CRITICALCVSS 9.2EG 9.22026-01-26
By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the password was not enforced.
- CVE-2026-97064CRITICALCVSS 9.1EG 9.12026-09-25
X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailO…
- CVE-2026-44761CRITICALCVSS 9.1EG 9.12026-07-14
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use th…
- CVE-2025-12218CRITICALCVSS 9.1EG 9.12025-10-25
Weak Default Credentials.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- CVE-2025-12217CRITICALCVSS 9.1EG 9.12025-10-25
SNMP Default Community String (public).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- CVE-2025-51535CRITICALCVSS 9.1EG 9.12025-08-04
Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.
- CVE-2025-29629CRITICALCVSS 9.1EG 9.12025-07-25
Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gar…
- CVE-2024-12856CRITICALCVSS 7.2EG 9.02024-12-27
The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 allows authenticated and remote attackers to execute arbitrary OS commands over HTTP when …
Map vulnerabilities like CWE-1392 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1392 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →