← Back
CWE-1188

307 CVEs • Abstraction: Base

Initialization of a Resource with an Insecure Default

The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.

JSON object

Loading...

CVEs (307)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Learningdigital
1Orca Hcm
Jun 17, 2026
Jul 19, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege w...Show more
The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege without logging in.Show less
1Depstech
1Wifi Digital Microscope 3 Firmware
Jun 17, 2026
Jul 15, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
DEPSTECH WiFi Digital Microscope 3 has a default SSID of Jetion_xxxxxxxx with a password of 12345678.
1Intel
944Atom C3000
Atom C3308Atom C3336+941 more
Jun 17, 2026
Jul 14, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local access.
1Tieline
1Ip Audtio Gateway Firmware
Jun 17, 2026
Jul 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web Administrative Interface could allow an unauthenticated user to access a sensitive part of the system...Show more
Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web Administrative Interface could allow an unauthenticated user to access a sensitive part of the system with a high privileged account.Show less
1Google
1Android
Jun 17, 2026
Jun 22, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In permission declarations of DeviceAdminReceiver.java, there is a possible lack of broadcast protection due to an insecure default value. This could lead to local escalation of privilege with no additional execution pri...Show more
In permission declarations of DeviceAdminReceiver.java, there is a possible lack of broadcast protection due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-170639543Show less
1Dlink
1Dir 2640 Us Firmware
Jul 9, 2026
Jun 16, 2021
N/A· v4
8.1 HIGH· v3
4.8 MEDIUM· v2
D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in the way of whole network monitoring, and this function uses the original...Show more
D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in the way of whole network monitoring, and this function uses the original default password and port. An attacker can easily use telnet to log in, modify routing information, monitor the traffic of all devices under the router, hijack DNS and phishing attacks. In addition, this interface is likely to be questioned by customers as a backdoor, because the interface should not be exposed.Show less
1Dell
1Emc Integrated System For Microsoft Azure Stack Hub Firmware
Jun 17, 2026
May 6, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could poten...Show more
Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit this to log in to the system to gain root privileges.Show less
1Google
1Android
Jun 17, 2026
Apr 13, 2021
N/A· v4
6.6 MEDIUM· v3
4.4 MEDIUM· v2
In LK, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution pri...Show more
In LK, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-180427272Show less
1Cohesity
1Cohesity Dataplatform
Jun 17, 2026
Apr 2, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Undocumented Default Cryptographic Key Vulnerability in Cohesity DataPlatform version 6.3 prior 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. The ssh key can provide an attacker access to the linux system in the aff...Show more
Undocumented Default Cryptographic Key Vulnerability in Cohesity DataPlatform version 6.3 prior 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. The ssh key can provide an attacker access to the linux system in the affected version.Show less
1Svakom
1Siime Eye Firmware
Jun 17, 2026
Feb 8, 2021
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. By sending a set_params.cgi?telnetd=1&save=1&reboot=1 request to the webserver, it is possible to enable the telnet interface on the device. The t...Show more
An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. By sending a set_params.cgi?telnetd=1&save=1&reboot=1 request to the webserver, it is possible to enable the telnet interface on the device. The telnet interface can then be used to obtain access to the device with root privileges via a reecam4debug default password. This default telnet password is the same across all Siime Eye devices. In order for the attack to be exploited, an attacker must be physically close in order to connect to the device's Wi-Fi access point.Show less
1Psyprax
1Psyprax
Jun 17, 2026
Feb 5, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
An issue was discovered in Psyprax before 3.2.2. The Firebird database is accessible with the default user sysdba and password masterke after installation. This allows any user to access it and read and modify the conten...Show more
An issue was discovered in Psyprax before 3.2.2. The Firebird database is accessible with the default user sysdba and password masterke after installation. This allows any user to access it and read and modify the contents, including passwords. Local database files can be accessed directly as well.Show less
1Tk Star
1Q90 Junior Gps Horloge Firmware
Jun 17, 2026
Feb 1, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SMS commands. This can be used to set up a voice communication channel from the watch to any telephone...Show more
An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SMS commands. This can be used to set up a voice communication channel from the watch to any telephone number, initiated by sending a specific SMS and using the default password, e.g., pw,<password>,call,<mobile_number> triggers an outbound call from the watch. The password is sometimes available because of CVE-2019-20471.Show less
1Google
1Android
Jun 17, 2026
Dec 14, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction is not needed for expl...Show more
In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-171413798Show less
1Google
1Android
Jun 17, 2026
Dec 14, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insecure default value. This could lead to local escalation of privilege via tapjacking with no additional execution privileg...Show more
In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insecure default value. This could lead to local escalation of privilege via tapjacking with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-141745510Show less
1Vmware
1Sd Wan Orchestrator
Jun 17, 2026
Nov 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash att...Show more
The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash attack.Show less
1Basetech
1Ge 131 Bt 1837836 Firmware
Jun 17, 2026
Nov 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute arbitrary system commands as the root user.
1Airleader
1Airleader Master Control
Jun 17, 2026
Nov 16, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution.
1Intel
23Nuc 8 Mainstream G Kit Nuc8i5inh Firmware
Nuc 8 Mainstream G Kit Nuc8i7inh FirmwareNuc 8 Mainstream G Mini Pc Nuc8i5inh Firmware+20 more
Jun 17, 2026
Nov 12, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Insecure default variable initialization in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Thunderbolt Dch Driver
Jun 17, 2026
Nov 12, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Insecure default variable initialization in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow a privileged user to potentially enable information disclosure via local access.
1Intel
3Converged Security And Manageability Engine
Server Platform ServicesTrusted Execution Technology
Jun 17, 2026
Nov 12, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4....Show more
Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4.0.30, Intel(R) SPS versions before E5_04.01.04.400, E3_04.01.04.200, SoC-X_04.00.04.200 and SoC-A_04.00.04.300 may allow an unauthenticated user to potentially enable escalation of privileges via physical access.Show less