The product uses a default cryptographic key for potentially critical functionality.
Volume of CVEs assigned to CWE-1394 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55049CRITICAL Use of Default Cryptographic Key (CWE-1394) | Sep 9, 2025 | 9.1 | 32 | NO | NO |
CVE-2025-41742CRITICAL Sprecher Automations SPRECON-E-C, SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allows | Dec 2, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-44954CRITICAL RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account. | Aug 4, 2025 | 9.8 | 31 | NO | NO |
CVE-2024-48956CRITICAL Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to a service endpoint resulting in remote co | Dec 9, 2024 | 9.8 | 30 | NO | NO |
CVE-2026-5039HIGH TP-Link TL-WR841N v13 uses DES-CBC encryption in the TDDPv2 debug protocol with a cryptographic key derived from default web management credentials, making the key predictable if d | Apr 23, 2026 | 8.8 | 29 | NO | NO |
CVE-2025-41744CRITICAL Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confid | Dec 2, 2025 | 9.1 | 29 | NO | NO |
CVE-2026-54887MEDIUM Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computation during the startup window, enabling source address verific | Jul 2, 2026 | 4.8 | 27 | NO | NO |
CVE-2024-1275CRITICAL Use of Default Cryptographic Key vulnerability in Baxter Welch Allyn Connex Spot Monitor may allow Configuration/Environment Manipulation.This issue affects Welch Allyn Connex Spot | May 31, 2024 | 9.1 | 26 | NO | NO |
CVE-2026-20709MEDIUM Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Series, Intel(R) Celeron(R) Processor N Serie | Apr 8, 2026 | 6.6 | 22 | NO | NO |
CVE-2024-11619HIGH A vulnerability, which was classified as problematic, has been found in macrozheng mall up to 1.0.3. Affected by this issue is some unknown functionality of the component JWT Token | Nov 22, 2024 | 8.1 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.