CWE-1188
307 CVEs • Abstraction: Base
Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.
CVEs (307)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1D Link 2Dir 550a Firmware Dir 604m FirmwareNov 21, 2024 May 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can use a default TELNET account to get unauthorized access to vulnerable devices, aka a backdoor access vulnerability. |
4Apache CanonicalDebian+1 more8Debian Linux Oncommand InsightOncommand Unified Manager+5 moreJun 17, 2026 May 16, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected...Show more |
1Commscope 1Arris Tg1682g Firmware Nov 21, 2024 May 14, 2018 N/A· v4 6.6 MEDIUM· v3 3.5 LOW· v2 Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices are distributed by some ISPs with a default password of "password" for the admin account that is used over an unencrypted http://192.168.0.1 connection, which...Show more |
A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 could allow an unauthenticate...Show more |
1Qualcomm 27Mdm9206 Firmware Mdm9607 FirmwareMdm9635m Firmware+24 moreNov 21, 2024 Apr 11, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, S...Show more |
An issue was discovered on Tenda AC15 devices. A remote, unauthenticated attacker can make a request to /goform/telnet, creating a telnetd service on the device. This service is password protected; however, several defau...Show more |
1Cisco 1Virtual Managed Services Nov 21, 2024 Feb 22, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to gain administrative access to an affected sys...Show more |
1Siemens 7Ruggedcom Ros Scalance Xb 200 FirmwareScalance Xc 200 Firmware+4 moreMay 13, 2026 Dec 26, 2017 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain conditions. This could allow an attacker located in the adjacent network of the targeted device t...Show more |
An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can b...Show more |
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected devices could allow u...Show more |
EMC Elastic Cloud Storage (ECS) before 3.1 is affected by an undocumented account vulnerability that could potentially be leveraged by malicious users to compromise the affected system. |
1Cisco 2Web Security Appliance Web Security Virtual ApplianceMay 13, 2026 Jul 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker to...Show more |
1Cisco 1Ultra Services Framework Element Manager May 13, 2026 Jun 13, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker to log in to the device with the privileges of the root user, aka an Insecure Default Account Information Vu...Show more |
1Cisco 1Elastic Services Controller May 13, 2026 Jun 13, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the admin user, aka an Insecure Default Administrator Credentials Vu...Show more |
1Cisco 1Elastic Services Controller May 13, 2026 Jun 13, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux root user, aka an Insecure Default Password Vulnerability. More Information...Show more |
1Cisco 1Ultra Services Framework Element Manager May 13, 2026 Jun 13, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in to the affected device using default credentials present on...Show more |
1Cisco 1Ultra Services Framework Element Manager May 13, 2026 Jun 13, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in as an admin or oper user of the affected device, aka an Inse...Show more |
1Cisco 1Ultra Services Framework Staging Server May 13, 2026 Jun 13, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability in Cisco Ultra Services Framework Staging Server could allow an authenticated, remote attacker with access to the management network to log in as an admin user of the affected device, aka an Insecure Defa...Show more |
1Cisco 1Elastic Services Controller May 13, 2026 Jun 13, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux admin user, aka an Insecure Default Credentials Vulnerability. More Informa...Show more |
An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can b...Show more |