CWE-1391
Allowed-with-ReviewUse of Weak Credentials
Abstraction: Class · Status: Incomplete
The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.
112 vulnerabilities reference this CWE, most recent first.
GHSA-3FGM-3M4R-2X8G
Vulnerability from github – Published: 2025-09-18 21:30 – Updated: 2025-09-18 21:30Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standard administrative means. An attacker with network access to the device can gain administrative access to the system.
{
"affected": [],
"aliases": [
"CVE-2025-30519"
],
"database_specific": {
"cwe_ids": [
"CWE-1391"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-09-18T21:15:47Z",
"severity": "CRITICAL"
},
"details": "Dover Fueling Solutions ProGauge MagLink LX4 Devices\u00a0have default root credentials that cannot be changed through standard \nadministrative means. An attacker with network access to the device can \ngain administrative access to the system.",
"id": "GHSA-3fgm-3m4r-2x8g",
"modified": "2025-09-18T21:30:57Z",
"published": "2025-09-18T21:30:57Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30519"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-261-07"
},
{
"type": "WEB",
"url": "https://www.doverfuelingsolutions.com/mea/en/products-and-solutions/automatic-tank-gauging/consoles/progauge-maglink-lx-4-console.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-3JG5-P6XV-G24V
Vulnerability from github – Published: 2026-09-03 15:32 – Updated: 2026-09-03 15:32Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services.
This issue affects mapp Audit used in mapp Services: before 6.8.0.
{
"affected": [],
"aliases": [
"CVE-2026-79679"
],
"database_specific": {
"cwe_ids": [
"CWE-1391"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-03T13:06:10Z",
"severity": "HIGH"
},
"details": "Use of Weak Credentials vulnerability in B\u0026R Industrial Automation GmbH mapp Audit used in mapp Services.\n\nThis issue affects mapp Audit used in mapp Services: before 6.8.0.",
"id": "GHSA-3jg5-p6xv-g24v",
"modified": "2026-09-03T15:32:13Z",
"published": "2026-09-03T15:32:13Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79679"
},
{
"type": "WEB",
"url": "https://br-cws-assets.de-fra-1.linodeobjects.com/SA26P012-28f0e5aa.pdf"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-47GJ-J96M-3HHG
Vulnerability from github – Published: 2024-02-02 00:31 – Updated: 2025-08-07 21:31Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.
{
"affected": [],
"aliases": [
"CVE-2024-1039"
],
"database_specific": {
"cwe_ids": [
"CWE-1391",
"CWE-287",
"CWE-798"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-01T22:15:55Z",
"severity": "CRITICAL"
},
"details": "Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.",
"id": "GHSA-47gj-j96m-3hhg",
"modified": "2025-08-07T21:31:03Z",
"published": "2024-02-02T00:31:26Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1039"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-032-01"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-4XG9-H72C-FXFM
Vulnerability from github – Published: 2025-07-31 06:30 – Updated: 2025-07-31 06:30ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected devices.
{
"affected": [],
"aliases": [
"CVE-2025-53558"
],
"database_specific": {
"cwe_ids": [
"CWE-1391"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-07-31T06:15:24Z",
"severity": "HIGH"
},
"details": "ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected devices.",
"id": "GHSA-4xg9-h72c-fxfm",
"modified": "2025-07-31T06:30:32Z",
"published": "2025-07-31T06:30:32Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-53558"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN66546573"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-5X9V-2JCX-698H
Vulnerability from github – Published: 2026-09-24 21:32 – Updated: 2026-09-24 21:32The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated attacker within WiFi range could potentially determine the remaining password characters through limited guessing and gain unauthorized access to the device network.
{
"affected": [],
"aliases": [
"CVE-2026-88761"
],
"database_specific": {
"cwe_ids": [
"CWE-1391"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-24T20:17:33Z",
"severity": "MODERATE"
},
"details": "The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated attacker within WiFi range could potentially determine the remaining password characters through limited guessing and gain unauthorized access to the device network.",
"id": "GHSA-5x9v-2jcx-698h",
"modified": "2026-09-24T21:32:49Z",
"published": "2026-09-24T21:32:49Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88761"
},
{
"type": "WEB",
"url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json"
},
{
"type": "WEB",
"url": "https://www.botslab.com/pages/about-botslab"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-01"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-624F-P4GG-QWG2
Vulnerability from github – Published: 2026-05-28 12:30 – Updated: 2026-05-28 12:30Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. An attacker who knows how passwords are generated can easily crack the default password if they have the device IMEI number.
This issue was fixed in version 1.00B16CP.
{
"affected": [],
"aliases": [
"CVE-2026-4377"
],
"database_specific": {
"cwe_ids": [
"CWE-1391"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-05-28T10:16:39Z",
"severity": "MODERATE"
},
"details": "Dlink\u00a0DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. An attacker who knows how passwords are generated can easily crack the default password if they have the device IMEI number.\n\nThis issue was fixed in version\u00a01.00B16CP.",
"id": "GHSA-624f-p4gg-qwg2",
"modified": "2026-05-28T12:30:34Z",
"published": "2026-05-28T12:30:34Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4377"
},
{
"type": "WEB",
"url": "https://cert.pl/posts/2026/05/CVE-2026-4377"
},
{
"type": "WEB",
"url": "https://www.dlink.com/pl/pl/products/dwr-1820-cp#support"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-65FR-GPW6-J777
Vulnerability from github – Published: 2023-05-22 21:30 – Updated: 2024-04-04 04:16Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely. OvrC cloud contains a hidden superuser account accessible through hard-coded credentials.
{
"affected": [],
"aliases": [
"CVE-2023-31240"
],
"database_specific": {
"cwe_ids": [
"CWE-1391",
"CWE-798"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-05-22T20:15:10Z",
"severity": "CRITICAL"
},
"details": "\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\nSnap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely. OvrC cloud contains a hidden superuser account accessible through hard-coded credentials.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n",
"id": "GHSA-65fr-gpw6-j777",
"modified": "2024-04-04T04:16:46Z",
"published": "2023-05-22T21:30:25Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31240"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-136-01"
},
{
"type": "WEB",
"url": "https://www.control4.com/docs/product/ovrc-software/release-notes/english/latest/ovrc-software-release-notes-rev-r.pdf"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L",
"type": "CVSS_V3"
}
]
}
GHSA-7CX5-PCXX-59Q4
Vulnerability from github – Published: 2024-10-15 12:30 – Updated: 2024-10-15 12:30An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.
{
"affected": [],
"aliases": [
"CVE-2024-45272"
],
"database_specific": {
"cwe_ids": [
"CWE-1391"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-15T11:15:11Z",
"severity": "HIGH"
},
"details": "An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.",
"id": "GHSA-7cx5-pcxx-59q4",
"modified": "2024-10-15T12:30:37Z",
"published": "2024-10-15T12:30:37Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45272"
},
{
"type": "WEB",
"url": "https://cert.vde.com/en/advisories/VDE-2024-068"
},
{
"type": "WEB",
"url": "https://cert.vde.com/en/advisories/VDE-2024-069"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-7RXX-X775-HWQ2
Vulnerability from github – Published: 2025-08-02 03:31 – Updated: 2025-11-03 21:34Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and password for the administrator account across all versions.
{
"affected": [],
"aliases": [
"CVE-2025-6077"
],
"database_specific": {
"cwe_ids": [
"CWE-1391"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-08-02T03:15:24Z",
"severity": "CRITICAL"
},
"details": "Partner Software\u0027s Partner Software Product and corresponding Partner Web application use the same default username and password for the administrator account across all versions.",
"id": "GHSA-7rxx-x775-hwq2",
"modified": "2025-11-03T21:34:17Z",
"published": "2025-08-02T03:31:21Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-6077"
},
{
"type": "WEB",
"url": "https://kb.cert.org/vuls/id/317469"
},
{
"type": "WEB",
"url": "https://partnersoftware.com/resources/software-release-info-4-32"
},
{
"type": "WEB",
"url": "https://www.kb.cert.org/vuls/id/317469"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-7WPM-58FR-6P69
Vulnerability from github – Published: 2025-02-06 21:32 – Updated: 2025-02-12 00:32An issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W-A1 allows a remote attacker to obtain sensitive information via the Weak default WiFi password generation algorithm in WiFi routers.
{
"affected": [],
"aliases": [
"CVE-2025-22936"
],
"database_specific": {
"cwe_ids": [
"CWE-1391",
"CWE-327"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-06T20:15:40Z",
"severity": "HIGH"
},
"details": "An issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W-A1 allows a remote attacker to obtain sensitive information via the Weak default WiFi password generation algorithm in WiFi routers.",
"id": "GHSA-7wpm-58fr-6p69",
"modified": "2025-02-12T00:32:15Z",
"published": "2025-02-06T21:32:09Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22936"
},
{
"type": "WEB",
"url": "https://sec.stanev.org/advisories/Smartcom_default_WPA_password.txt"
},
{
"type": "WEB",
"url": "http://smartcom.com"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
Mitigation
When the user changes or sets a password, check the password against a database of already compromised or breached passwords. These passwords are likely to be used in password guessing attacks.
No CAPEC attack patterns related to this CWE.