CWE-1188
307 CVEs • Abstraction: Base
Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.
CVEs (307)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege w...Show more |
1Depstech 1Wifi Digital Microscope 3 Firmware Jun 17, 2026 Jul 15, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 DEPSTECH WiFi Digital Microscope 3 has a default SSID of Jetion_xxxxxxxx with a password of 12345678. |
1Intel 944Atom C3000 Atom C3308Atom C3336+941 moreJun 17, 2026 Jul 14, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local access. |
1Tieline 1Ip Audtio Gateway Firmware Jun 17, 2026 Jul 1, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web Administrative Interface could allow an unauthenticated user to access a sensitive part of the system...Show more |
In permission declarations of DeviceAdminReceiver.java, there is a possible lack of broadcast protection due to an insecure default value. This could lead to local escalation of privilege with no additional execution pri...Show more |
D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in the way of whole network monitoring, and this function uses the original...Show more |
1Dell 1Emc Integrated System For Microsoft Azure Stack Hub Firmware Jun 17, 2026 May 6, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could poten...Show more |
In LK, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution pri...Show more |
1Cohesity 1Cohesity Dataplatform Jun 17, 2026 Apr 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Undocumented Default Cryptographic Key Vulnerability in Cohesity DataPlatform version 6.3 prior 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. The ssh key can provide an attacker access to the linux system in the aff...Show more |
An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. By sending a set_params.cgi?telnetd=1&save=1&reboot=1 request to the webserver, it is possible to enable the telnet interface on the device. The t...Show more |
An issue was discovered in Psyprax before 3.2.2. The Firebird database is accessible with the default user sysdba and password masterke after installation. This allows any user to access it and read and modify the conten...Show more |
1Tk Star 1Q90 Junior Gps Horloge Firmware Jun 17, 2026 Feb 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SMS commands. This can be used to set up a voice communication channel from the watch to any telephone...Show more |
In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction is not needed for expl...Show more |
In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insecure default value. This could lead to local escalation of privilege via tapjacking with no additional execution privileg...Show more |
The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash att...Show more |
1Basetech 1Ge 131 Bt 1837836 Firmware Jun 17, 2026 Nov 17, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute arbitrary system commands as the root user. |
1Airleader 1Airleader Master Control Jun 17, 2026 Nov 16, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution. |
1Intel 23Nuc 8 Mainstream G Kit Nuc8i5inh Firmware Nuc 8 Mainstream G Kit Nuc8i7inh FirmwareNuc 8 Mainstream G Mini Pc Nuc8i5inh Firmware+20 moreJun 17, 2026 Nov 12, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Insecure default variable initialization in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access. |
Insecure default variable initialization in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow a privileged user to potentially enable information disclosure via local access. |
1Intel 3Converged Security And Manageability Engine Server Platform ServicesTrusted Execution TechnologyJun 17, 2026 Nov 12, 2020 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4....Show more |