CWE-1392: Use of Default Credentials
The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.
101 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-12856 — Four-Faith Industrial Router adjust_sys_time OS Command Injection
- CVE-2025-8731 — TRENDnet TI-G160i/TI-PG102i/TPL-430AP SSH Service default credentials
- CVE-2025-55051 — CWE-1392: Use of Default Credentials
- CVE-2025-12218 — Weak Default Credentials
- CVE-2026-27751 — SODOLA SL902-SWTGW124AS <= 200.1.20 Use of Default Credentials
- CVE-2026-26366 — JUNG eNet SMART HOME server 2.2.1/2.3.1 Use of Default Credentials
- CVE-2026-22886 — OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product
- CVE-2025-35452 — Pan-Tilt-Zoom cameras default administrative credentials for web interface
- CVE-2025-35042 — Airship AI Acropolis default credentials
- CVE-2024-29844 — Default credentials on web interface of Evolution Controller Versions allows attackers to login and perform administrative functions
- CVE-2024-12286 — MOBATIME Network Master Clock has a use of default credentials vulnerability
- CVE-2025-12592 — Use of default login credentials in Legacy Vivotek Devices
- CVE-2025-10678 — Admin with default credentials in NetBird VPN
- CVE-2026-1803 — Ziroom ZHOME A0101 Dropbear SSH Service default credentials
- CVE-2025-59108 — Weak Default Passwords in dormakaba access manager
- CVE-2025-5124 — Sony SNC-M1 Administrative Interface default credentials
- CVE-2023-27573 — netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0
- CVE-2026-22273 — Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default C
- CVE-2025-7740 — Use of default credentials vulnerability in Hitachi Energy SuprOS product
- CVE-2025-6529 — 70mai M300 Telnet Service default credentials
Recently published
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity
- CVE-2026-76155 — Datiphy Data Management Center - Use of Default Credentials
- CVE-2026-65313 — Use of hard-coded VNC credentials in the engineering-workstation provisioning
- CVE-2026-68503 — LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 Dashboard
- CVE-2026-41939 — Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly
- CVE-2026-44761 — Insecure Sample Credentials in SAP Commerce Cloud
- CVE-2026-3144 — IBM API Connect Default Credentials
- CVE-2026-58466 — AutoBangumi < 3.2.8 - Hard-coded Default Credentials via add_default_user()
- CVE-2026-58453 — JAIOTlink C492A-W6 4.8.30.57701411 Hard-coded Credentials via anyka_ipc
- CVE-2026-46386 — OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`
- CVE-2026-44273 — Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high
- CVE-2026-32652 — Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Credentials" vulnerability. A low privileged att
- CVE-2026-50005 — Brickcom Cameras Use of Default Credentials
- CVE-2026-9844 — Vulnerability in navify® Digital Pathology
- CVE-2026-42941 — MacGregor Voyage Data Recorder (VDR) G4e Use of Default Credentials
- CVE-2026-45039 — RustFS: Internode RPC HMAC secret falls back to public default credential, enabling peer impersonation
- CVE-2026-7365 — IBM Operations Analytics - Log Analysis is affected by Information disclosure due to default passwords not being forced to be changed on post-installation
- CVE-2025-36221 — Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops.
- CVE-2026-44159 — Tyler Identity Local (TID-L) default administrative credentials
- CVE-2026-7428 — Insecure default administrative credentials in AlloyDB for PostgreSQL