Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-1391

Use of Weak Credentials

The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.

53
Assigned CVEs
231st
Commonality Rank
7.8
Avg CVSS
0.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-1391 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2023
3 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

53 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-51978CRITICAL
An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first disco
Jun 25, 20259.866NOYES
CVE-2025-53558HIGH
ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected dev
Jul 31, 20258.844NOYES
CVE-2026-45363CRITICAL
ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forg
Jul 14, 20269.139NONO
CVE-2026-39920CRITICAL
BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allo
Apr 24, 20269.837NONO
CVE-2026-49852HIGH
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-forg
Jul 17, 20268.735NONO
CVE-2026-8076CRITICAL
Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentication. The system supports the
May 8, 20269.333NONO
CVE-2026-22886CRITICAL
OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin)
Mar 3, 20269.833NONO
CVE-2026-35089HIGH
In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can be obtained without authentication. An unauthenti
May 27, 20268.732NONO
CVE-2026-22910CRITICAL
The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the
Jan 15, 20269.132NONO
CVE-2025-6077CRITICAL
Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and password for the administrator account across all versions.
Aug 2, 20259.832NONO
View all 53 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
9%
19%
5.0-5.9
13%
16%
6.0-6.9
26%
26%
7.0-7.9
17%
11%
8.0-8.9
28%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.9% of CVEs· 92nd percentile
Nuclei
2 CVEs
3.8% of CVEs· 94th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products