The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.
Volume of CVEs assigned to CWE-1391 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
53 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-51978CRITICAL An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first disco | Jun 25, 2025 | 9.8 | 66 | NO | YES |
CVE-2025-53558HIGH ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected dev | Jul 31, 2025 | 8.8 | 44 | NO | YES |
CVE-2026-45363CRITICAL ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forg | Jul 14, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-39920CRITICAL BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allo | Apr 24, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-49852HIGH joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-forg | Jul 17, 2026 | 8.7 | 35 | NO | NO |
CVE-2026-8076CRITICAL Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentication. The system supports the | May 8, 2026 | 9.3 | 33 | NO | NO |
CVE-2026-22886CRITICAL OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires
authentication. However, the product ships with a default administrative account (admin/
admin) | Mar 3, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-35089HIGH In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can be obtained without authentication. An unauthenti | May 27, 2026 | 8.7 | 32 | NO | NO |
CVE-2026-22910CRITICAL The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the | Jan 15, 2026 | 9.1 | 32 | NO | NO |
CVE-2025-6077CRITICAL Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and password for the administrator account across all versions. | Aug 2, 2025 | 9.8 | 32 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.