CWE-1392— Use of Default Credentials
The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.— MITRE CWE catalog
121 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1392page 2 of 3
- CVE-2026-9844HIGHCVSS 8.8EG 8.82026-06-02
Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Passwords. This issue affects navify Digital Pathology: from 2.0.0 before 2.4.1.
- CVE-2025-7740HIGHCVSS 8.8EG 8.82026-01-28
Default credentials vulnerability exists in SuprOS product. If exploited, this could allow an authenticated local attacker to use an admin account created during product deployment.
- CVE-2026-22273HIGHCVSS 8.8EG 8.82026-01-23
Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default Credentials vulnerability in the OS. A low privileged attacker with remote access could potentially exploit this vulnera…
- CVE-2025-6529HIGHCVSS 8.8EG 8.82025-06-23
A vulnerability was found in 70mai M300 up to 20250611 and classified as critical. Affected by this issue is some unknown functionality of the component Telnet Service. The manipulation leads to use of default credentials. The attack needs…
- CVE-2024-4007HIGHCVSS 8.8EG 8.82024-07-01
Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.
- CVE-2024-28093HIGHCVSS 8.8EG 8.82024-03-26
The TELNET service of AdTran NetVanta 3120 18.01.01.00.E devices is enabled by default, and has default credentials for a root-level account.
- CVE-2024-6788HIGHCVSS 8.6EG 8.62024-08-13
A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password.
- CVE-2025-54756HIGHCVSS 8.4EG 8.42026-02-12
BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default password that is guessable with knowledge of the device information. The latest release fixes this issue for new installati…
- CVE-2024-12902HIGHCVSS 8.4EG 8.42024-12-23
ANCHOR from Global Wisdom Software is an integrated product running on a Windows virtual machine. The underlying Windows OS of the product contains high-privilege service accounts. If these accounts use default passwords, attackers could r…
- CVE-2026-7365HIGHCVSS 7.8EG 8.42026-05-27
IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass …
- CVE-2026-42941HIGHCVSS 8.3EG 8.32026-05-29
The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change.
- CVE-2024-4622HIGHCVSS 8.3EG 8.32024-05-15
If misconfigured, alpitronic Hypercharger EV charging devices can expose a web interface protected by authentication. If the default credentials are not changed, an attacker can use public knowledge to access the device as an administra…
- CVE-2024-39584HIGHCVSS 8.2EG 8.22024-08-28
Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Secure Boot bypass and arbitrary code execution.
- CVE-2026-90456HIGHCVSS 8.1EG 8.12026-09-11
An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the set…
- CVE-2026-65313HIGHCVSS 8.1EG 8.12026-07-31
A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker wit…
- CVE-2026-1803HIGHCVSS 8.1EG 8.12026-02-03
A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes use of default credentials. Remote exploitation of the attack is possible. The co…
- CVE-2025-5124HIGHCVSS 8.1EG 8.12025-05-24
A vulnerability classified as critical has been found in Sony SNC-M1, SNC-M3, SNC-RZ25N, SNC-RZ30N, SNC-DS10, SNC-CS3N and SNC-RX570N up to 1.30. This affects an unknown part of the component Administrative Interface. The manipulation lead…
- CVE-2024-39747HIGHCVSS 8.1EG 8.12024-08-31
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.
- CVE-2024-10476HIGHCVSS 8.0EG 8.02024-12-17
Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modify or delete data, including sensitive information such as protected health information (PHI) and per…
- CVE-2023-43844HIGHCVSS 8.0EG 8.02024-05-28
Aten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged web interface account. The user is not asked to change the credentials after first login. If not changed, attackers can log in to the web interface and gain admini…
- CVE-2026-32652HIGHCVSS 7.8EG 7.82026-06-17
Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Credentials" vulnerability. A low privileged attacker with console access could potentially exploit this vulnerability to gain Filesystem access. This vulnerability on…
- CVE-2025-22460HIGHCVSS 7.8EG 7.82025-05-13
Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.
- CVE-2024-5245HIGHCVSS 7.8EG 7.82024-05-23
NETGEAR ProSAFE Network Management System Default Credentials Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System…
- CVE-2026-50005HIGHCVSS 7.7EG 7.72026-06-11
Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds.
- CVE-2024-12013HIGHCVSS 7.6EG 7.62025-02-13
A CWE-1392 “Use of Default Credentials” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The device exposes an FTP server with default and easy-to-guess admin credentials. A remote attacker capable of …
- CVE-2025-36221HIGHCVSS 7.5EG 7.52026-05-26
IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an a…
- CVE-2026-31837HIGHCVSS 7.5EG 7.52026-03-10
Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of…
- CVE-2026-1972HIGHCVSS 7.5EG 7.52026-02-06
A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Performing a manipulation of the argument Username/Password results in use of default credentials. The attack may be initiated…
- CVE-2025-58744HIGHCVSS 7.5EG 7.52026-01-20
Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows decryption of document archive files using credentials decrypted with hard-coded application en…
- CVE-2020-36915HIGHCVSS 7.5EG 7.52026-01-06
Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials to gain root-level …
- CVE-2018-25147HIGHCVSS 7.5EG 7.52025-12-24
Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to the device by logging …
- CVE-2025-35114HIGHCVSS 7.5EG 7.52025-08-26
Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The password hash is known for at least one of the accounts and the credentials could be cracked offline. Users should upgra…
- CVE-2025-8530HIGHCVSS 7.5EG 7.52025-08-04
A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of the file eladmin-system\src\main\resources\config\application-prod.yml of the compone…
- CVE-2024-13893HIGHCVSS 7.5EG 7.52025-03-06
Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, might share same credentials for telnet service. Hash of the password can be retrieved through physical access to SPI con…
- CVE-2024-54015HIGHCVSS 7.5EG 7.52025-02-11
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 6MD86 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 6MD89 (CP300) (All versi…
- CVE-2025-23012HIGHCVSS 7.5EG 7.52025-01-23
Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with default credentials and privileges to read read local files by manipulating datastreams. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer mainta…
- CVE-2024-6245HIGHCVSS 7.4EG 7.42024-10-28
Use of Default Credentials vulnerability in Maruti Suzuki SmartPlay on Linux (Infotainment Hub modules) allows attacker to try common or default usernames and passwords.The issue was detected on a 2022 Maruti Suzuki Brezza in India Market.…
- CVE-2024-27158HIGHCVSS 7.4EG 7.42024-06-14
All the Toshiba printers share the same hardcoded root password. As for the affected products/models/versions, see the reference URL.
- CVE-2024-31069HIGHCVSS 7.4EG 7.42024-04-12
IO-1020 Micro ELD web server uses a default password for authentication.
- CVE-2024-30210HIGHCVSS 7.4EG 7.42024-04-12
IO-1020 Micro ELD uses a default WIFI password that could allow an adjacent attacker to connect to the device.
- CVE-2026-90498HIGHCVSS 7.3EG 7.32026-09-13
A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. Remote exploitation of the attack is possible. The ex…
- CVE-2025-54137HIGHCVSS 7.3EG 7.32025-07-22
HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend. Versions 11.0.9 and below were distributed with hardcoded default credentials for the user and superuser accounts. Additionally, the application has defa…
- CVE-2025-1160HIGHCVSS 7.3EG 7.32025-02-10
A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument username/password leads…
- CVE-2025-0482HIGHCVSS 7.3EG 7.32025-01-15
A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. This affects an unknown part of the file /fladmin/user_recoverpwd.php. The manipulation leads to use of default credentials. It is possible to in…
- CVE-2024-7898HIGHCVSS 7.3EG 7.32024-08-17
A vulnerability classified as critical was found in Tosei Online Store Management System ネット店舗管理システム 4.02/4.03/4.04. This vulnerability affects unknown code of the component Backend. The manipulation leads to use of d…
- CVE-2025-2398HIGHCVSS 7.2EG 7.22025-03-17
A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been rated as critical. This issue affects some unknown processing of the component CLI su Command Hand…
- CVE-2026-28713HIGHCVSS 7.1EG 7.12026-03-06
Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyber Protect Cloud Agent (VMware) before build 36943, Acronis Cyber Protect 17 (VMware) before build 41186.
- CVE-2024-46899HIGHCVSS 7.1EG 7.12025-04-22
Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentials leakage vulnerability.This issue affects Hitachi Ops Center Common Services: from 10.0.0-00 before 11.0.0-04; Hitach…
- CVE-2024-45068HIGHCVSS 7.1EG 7.12024-12-03
Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.3-00; Hitachi Ops Center OVA: from 10…
- CVE-2023-40704HIGHCVSS 6.8EG 7.12024-07-18
The product does not require unique and complex passwords to be created during installation. Using Philips's default password could jeopardize the PACS system if the password was hacked or leaked. An attacker could gain access to the da…
Map vulnerabilities like CWE-1392 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1392 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →