CWE-1392
106 CVEs • Abstraction: Base
Use of Default Credentials
The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.
CVEs (106)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sodola Network 1Sl902 Swtgw124as Firmware Jun 17, 2026 Feb 27, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attackers can authenticate...Show more |
1Tattile 10Anpr Mobile Firmware Axle Counter FirmwareBasic Mk2 Firmware+7 moreJun 17, 2026 Feb 24, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the mana...Show more |
1Jung Group 1Enet Smart Home Jun 17, 2026 Feb 15, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Unauthenticated attack...Show more |
BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default password that is guessable with knowledge of the device information. The latest release fixes this issue...Show more |
1Edimax 1Br 6208ac Firmware Jun 17, 2026 Feb 6, 2026 5.5 MEDIUM· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Performing a manipulation of the argument Username/Password results in use of default credentials. The atta...Show more |
A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes use of default credentials. Remote exploitation of the attack...Show more |
Default credentials vulnerability exists in SuprOS
product. If exploited, this could allow an authenticated
local attacker to use an admin account created during
product deployment. |
By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the password was not enforced. |
1Dell 2Elastic Cloud Storage ObjectscaleJun 17, 2026 Jan 23, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default Credentials vulnerability in the OS. A low privileged attacker with remote access could potentially e...Show more |
1Milner 1Imagedirector Capture Jun 17, 2026 Jan 20, 2026 6.9 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows decryption of document archive files using credentials decrypted with hard-co...Show more |
Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials...Show more |
JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the device with administrative privileges. |
1Microhardcorp 11Bullet 3g Firmware Bullet Lte FirmwareBulletplus Firmware+8 moreJan 26, 2026 Dec 24, 2025 9.3 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to the...Show more |
COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclose RTSP stream. Attackers can exploit this by sending a POST request with the 'passkey' parameter set...Show more |
1Thermofisher 1Torrent Suite Software Jun 17, 2026 Dec 4, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The ionadmin user account can be used to authenticate to default deployments wi...Show more |
Legacy Vivotek Device firmware uses default credetials for the root and user login accounts. |
1Azure Access 2Blu Ic2 Firmware Blu Ic4 FirmwareJun 17, 2026 Oct 25, 2025 10.0 CRITICAL· v4 9.1 CRITICAL· v3 N/A· v2 Weak Default Credentials.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
1Azure Access 2Blu Ic2 Firmware Blu Ic4 FirmwareJun 17, 2026 Oct 25, 2025 6.9 MEDIUM· v4 9.1 CRITICAL· v3 N/A· v2 SNMP Default Community String (public).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL. This issue affects instances installed using vendor's provided script. This is...Show more |
170mai 1X200 Firmware Jun 17, 2026 Oct 19, 2025 5.5 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality of the component HTTP Web Server. The manipulation leads to use of default credentials. The attack c...Show more |