CWE-1393: Use of Default Password
The product uses default passwords for potentially critical functionality.
37 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-26793 — The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with defaul
- CVE-2025-26701 — An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead
- CVE-2024-51555 — Force Change of Default Credentials
- CVE-2026-22886 — OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product
- CVE-2025-8077 — NeuVector admin account has insecure default password
- CVE-2025-27690 — Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthent
- CVE-2025-66050 — No password set for administrative account in Vivotek IP7137 cameras
- CVE-2024-29021 — SSRF into Sandbox Escape through Unsafe Default Configuration
- CVE-2025-2766 — 70mai A510 Use of Default Password Authentication Bypass Vulnerability
- CVE-2024-49559 — Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password
- CVE-2024-43659 — Plaintext default credentials in firmware
- CVE-2026-5269 — Navigator NCS and MCP System Accounts with Default Passwords
- CVE-2026-35075 — Hardcoded default Password for Service Account
- CVE-2026-24429 — Tenda W30E V2 Hardcoded Default Password for Built-in Account
- CVE-2026-69657 — XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in
- CVE-2026-33784 — JSI Virtual Lightweight Collector: Default password is not required to be changed which allows unauthorized high-privileged access
- CVE-2024-13966 — ZKTeco BioTime default password
- CVE-2025-43799 — Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 202
- CVE-2025-14917 — IBM WebSphere Application Server Liberty could provide weaker than expected security
- CVE-2026-19851 — Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5
Recently published
- CVE-2026-69657 — XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in
- CVE-2026-82698 — sambitraj Student-Management-System aca.sql default password
- CVE-2026-19851 — Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5
- CVE-2026-5269 — Navigator NCS and MCP System Accounts with Default Passwords
- CVE-2026-54445 — Vantage6: Set admin user and password from environment or configuration
- CVE-2026-35075 — Hardcoded default Password for Service Account
- CVE-2026-8672 — Default credentials for internal DB
- CVE-2026-33784 — JSI Virtual Lightweight Collector: Default password is not required to be changed which allows unauthorized high-privileged access
- CVE-2025-14917 — IBM WebSphere Application Server Liberty could provide weaker than expected security
- CVE-2026-22886 — OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product
- CVE-2026-24429 — Tenda W30E V2 Hardcoded Default Password for Built-in Account
- CVE-2025-66050 — No password set for administrative account in Vivotek IP7137 cameras
- CVE-2025-8077 — NeuVector admin account has insecure default password
- CVE-2025-43799 — Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 202
- CVE-2025-9589 — Cudy WR1200EA shadow default password
- CVE-2025-43021 — Poly Clariti Manager - Multiple Security Vulnerabilities
- CVE-2025-2766 — 70mai A510 Use of Default Password Authentication Bypass Vulnerability
- CVE-2024-13966 — ZKTeco BioTime default password
- CVE-2025-27690 — Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthent
- CVE-2025-2921 — Netis WF-2404 passwd default password