CWE-1188
307 CVEs • Abstraction: Base
Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.
CVEs (307)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ceragon 1Fiberair Ip 10 Firmware May 13, 2026 May 21, 2017 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Ceragon FibeAir IP-10 wireless radios through 7.2.0 have a default password of mateidu for the mateidu account (a hidden user account established by the vendor). This account can be accessed via both the web interface an...Show more |
1Tp Link 2C20i Firmware C2 FirmwareMay 13, 2026 Apr 25, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n has a backdoor admin account with the 1234 password, a backdoor guest account with the guest password, and a backdoor test...Show more |
Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to conduct DNS hijacking attacks by reconfiguring the built-in dnshijacker process. |
1Cisco 1Aironet Access Point Firmware May 13, 2026 Apr 6, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points running Cisco Mobility Express Software could allow an unauthenticated, remote attacker to take complete control of an affected dev...Show more |
1Schneider Electric 3Tableau Desktop Tableau ServerWonderware IntelligenceMay 13, 2026 Mar 8, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonderware Intelligence Versions 2014R3 and prior. These versions contain a system account that is installed by default. The...Show more |
1Schneider Electric 1Wonderware Historian May 13, 2026 Feb 13, 2017 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. Wonderware Historian creates logins with default passwords, which can allow a malicious entity to compromise Historian datab...Show more |
wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name. |