CWE-1391: Use of Weak Credentials
The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.
47 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-51978 — Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
- CVE-2026-22886 — OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product
- CVE-2025-30519 — Dover Fueling Solutions ProGauge MagLink LX4 Devices Use of Weak Credentials
- CVE-2024-43698 — Kieback&Peter DDC4000 Series Use of Weak Credentials
- CVE-2024-12728 — A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than versi
- CVE-2025-6523 — Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker t
- CVE-2025-59103 — Weak Default Passwords for SSH Access in dormakaba access manager
- CVE-2025-35970 — On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from t
- CVE-2025-53558 — ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge o
- CVE-2024-5634 — Longse model LBH30FE200W cameras, as well as products based on this device, make use of telnet passwords which follow a
- CVE-2025-2229 — Philips Intellispace Cardiovascular (ISCV) Use of Weak Credentials
- CVE-2024-43659 — Plaintext default credentials in firmware
- CVE-2026-8076 — Weak credentials vulnerability in the CashDro 3 web administration panel
- CVE-2026-39920 — BridgeHead FileStore < 24A Apache Axis2 Default Credentials RCE
- CVE-2024-52331 — ECOVACS lawnmowers and vacuums deterministic firmware encryption key
- CVE-2024-32759 — Johnson Controls Software House C●CURE 9000 installer password strength
- CVE-2026-45363 — `jwt` (Ruby gem) - empty-key HMAC bypass
- CVE-2026-44351 — fast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypass
- CVE-2026-22910 — The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the ris
- CVE-2025-59460 — Unsecure access configuration
Recently published
- CVE-2026-79679 — Use of Weak Credentials
- CVE-2026-66409 — DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password ma
- CVE-2026-66408 — The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affec
- CVE-2026-49852 — joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
- CVE-2026-45363 — `jwt` (Ruby gem) - empty-key HMAC bypass
- CVE-2026-57473 — A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911)
- CVE-2026-47325 — Weak password policy in ProjectsAndPrograms school-management-system
- CVE-2026-4377 — Use of Weak Credentials in D-Link DWR-X1820 router
- CVE-2026-35089 — Use of Weak Credentials in Slican telephone exchanges
- CVE-2026-44351 — fast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypass
- CVE-2026-8076 — Weak credentials vulnerability in the CashDro 3 web administration panel
- CVE-2026-39920 — BridgeHead FileStore < 24A Apache Axis2 Default Credentials RCE
- CVE-2026-23853 — Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,
- CVE-2026-22886 — OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product
- CVE-2026-24449 — For WRC-X1500GS-B and WRC-X1500GSA-B, the initial passwords can be calculated easily from the system information.
- CVE-2025-59103 — Weak Default Passwords for SSH Access in dormakaba access manager
- CVE-2026-22920 — The device's passwords have not been adequately salted, making them vulnerable to password extraction attacks.
- CVE-2026-22910 — The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the ris
- CVE-2025-59460 — Unsecure access configuration
- CVE-2025-30519 — Dover Fueling Solutions ProGauge MagLink LX4 Devices Use of Weak Credentials