The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.
Volume of CVEs assigned to CWE-1392 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
106 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-12856HIGH The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 allows authenticated and remote | Dec 27, 2024 | 7.2 | 70 | NO | NO |
CVE-2026-26341CRITICAL Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissio | Feb 24, 2026 | 9.8 | 45 | NO | YES |
CVE-2026-44761CRITICAL SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. | Jul 14, 2026 | 9.1 | 43 | NO | NO |
CVE-2026-58466CRITICAL AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly kn | Jul 2, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-58453CRITICAL JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized acce | Jul 1, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-46386CRITICAL OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the defaul | Jun 26, 2026 | 9.9 | 40 | NO | NO |
CVE-2026-3144CRITICAL IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credent | Jul 8, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-44159CRITICAL Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment. TID-L has not been distributed | May 19, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-42072CRITICAL Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. Prior to version 1.0.42-hotfix, the --address CLI flag | May 8, 2026 | 9.8 | 38 | NO | NO |
CVE-2024-4007HIGH Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured. | Jul 1, 2024 | 8.8 | 36 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.