CWE-1391 · 52 kayıt
Use of Weak Credentials
Bu sınıftaki CVE’ler
52 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2024-51978Silahlaştırılmış | Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.brother industries, ltd · dcp-j928n-w/b · CWE-1391 | Kritik9,8 | — | %15,7 | 25 Haz 2025 |
39İzleyin | CVE-2024-12728İstismar yok | A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3)sophos · firewall firmware · CWE-1391 | Kritik9,8 | — | %0,9 | 19 Ara 2024 |
39İzleyin | CVE-2025-6077İstismar yok | Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and password for the admpartner software · partner web · CWE-1391 | Kritik9,8 | — | %0,7 | 1 Ağu 2025 |
39İzleyin | CVE-2022-46738İstismar yok | The affected product exposes multiple sensitive data fields of the affected product.dataprobe · iboot-pdu4-n20 firmware · CWE-1391 | Kritik9,8 | — | %0,6 | 22 May 2023 |
39İzleyin | CVE-2023-31240İstismar yok | Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely.snapone · orvc · CWE-1391 | Kritik9,8 | — | %0,5 | 22 May 2023 |
39İzleyin | CVE-2025-67114İstismar yok | Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware befCWE-1391 | Kritik9,8 | — | %0,5 | 19 Mar 2026 |
39İzleyin | CVE-2026-22886İstismar yok | OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication.eclipse · openmq · CWE-1391 | Kritik9,8 | — | %0,4 | 3 Mar 2026 |
39İzleyin | CVE-2023-0635İstismar yok | Privilege escalation to rootabb · aspect-ent-2 firmware · CWE-1391 | Kritik9,8 | — | %0,4 | 5 Haz 2023 |
38İzleyin | CVE-2025-6523İstismar yok | Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenticatdevolutions · devolutions server · CWE-1391 | Kritik9,5 | — | %0,4 | 22 Tem 2025 |
37İzleyin | CVE-2026-8076İstismar yok | Weak credentials vulnerability in the CashDro 3 web administration panelcashdro · cashdro 3 administration panel · CWE-1391 | Kritik9,3 | — | %0,6 | 8 May 2026 |
37İzleyin | CVE-2024-43698İstismar yok | Kieback&Peter DDC4000 Series Use of Weak Credentialskieback&peter · ddc4040e · CWE-1391 | Kritik9,3 | — | %0,4 | 22 Eki 2024 |
37İzleyin | CVE-2025-30519İstismar yok | Dover Fueling Solutions ProGauge MagLink LX4 Devices Use of Weak Credentialsdover fueling solutions · progauge maglink lx 4 · CWE-1391 | Kritik9,3 | — | %0,4 | 18 Eyl 2025 |
37İzleyin | CVE-2026-22094İstismar yok | Weak root password in EVbee DC 80evbee · dc 80 · CWE-1391 | Kritik9,3 | — | — | 1 gün önce |
36İzleyin | CVE-2026-22910İstismar yok | The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized acsick · tdc-x401gl firmware · CWE-1391 | Kritik9,1 | — | %0,5 | 15 Oca 2026 |
36İzleyin | CVE-2025-59103İstismar yok | Weak Default Passwords for SSH Access in dormakaba access managerdormakaba · access manager 92xx-k5 · CWE-1391 | Kritik9,2 | — | %0,4 | 26 Oca 2026 |
35İzleyin | CVE-2023-48257İstismar yok | The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) witbosch · nexo-os · CWE-1391 | Yüksek8,8 | — | %0,5 | 10 Oca 2024 |
35İzleyin | CVE-2024-29071İstismar yok | HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue.kddi corporation · hgw bl1500hm · CWE-1391 | Yüksek8,8 | — | %0,4 | 25 Mar 2024 |
34İzleyin | CVE-2025-53558Kavram kanıtı | ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K.zte japan. k.k. · zxhn-f660t · CWE-1391 | Yüksek8,7 | — | %1,4 | 31 Tem 2025 |
34İzleyin | CVE-2026-35089İstismar yok | Use of Weak Credentials in Slican telephone exchangesslican · ipx · CWE-1391 | Yüksek8,7 | — | %0,6 | 27 May 2026 |
34İzleyin | CVE-2024-45722İstismar yok | Ruijie Reyee OS Use of Weak Credentialsruijienetworks · reyee os · CWE-1391 | Yüksek8,7 | — | %0,5 | 6 Ara 2024 |
34İzleyin | CVE-2025-35970İstismar yok | On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from the information availseiko epson · multiple epson product · CWE-1391 | Yüksek8,7 | — | %0,5 | 7 Ağu 2025 |
34İzleyin | CVE-2024-5634İstismar yok | Longse model LBH30FE200W cameras, as well as products based on this device, make use of telnet passwords which follow a specific pattern.longse technology · lbh30fe200w · CWE-1391 | Yüksek8,6 | — | %0,2 | 9 Tem 2024 |
34İzleyin | CVE-2025-2229İstismar yok | Philips Intellispace Cardiovascular (ISCV) Use of Weak Credentialsphilips · intellispace cardiovascular (iscv) · CWE-1391 | Yüksek8,5 | — | %0,1 | 13 Mar 2025 |
34İzleyin | GHSA-phh4-3hmm-24rxİstismar yok | Duplicate Advisory: Juju makes Use of Weak CredentialsGo · github.com/juju/juju · CWE-1391 | Yüksek8,7 | — | — | 2 Eki 2024 |
33İzleyin | CVE-2026-23853İstismar yok | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release verdell · powerprotect dp series appliance · CWE-1391 | Yüksek8,4 | — | %0,2 | 17 Nis 2026 |
- CVE-2024-5197844Planlayın
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
KritikCVSS 9,8SilahlaştırılmışEPSS %16brother industries, ltd · dcp-j928n-w/b25 Haz 2025
- CVE-2024-1272839İzleyin
A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3)
KritikCVSS 9,8İstismar yokEPSS %1sophos · firewall firmware19 Ara 2024
- CVE-2025-607739İzleyin
Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and password for the adm
KritikCVSS 9,8İstismar yokEPSS %1partner software · partner web1 Ağu 2025
- CVE-2022-4673839İzleyin
The affected product exposes multiple sensitive data fields of the affected product.
KritikCVSS 9,8İstismar yokEPSS %1dataprobe · iboot-pdu4-n20 firmware22 May 2023
- CVE-2023-3124039İzleyin
Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely.
KritikCVSS 9,8İstismar yokEPSS %1snapone · orvc22 May 2023
- CVE-2025-6711439İzleyin
Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware bef
KritikCVSS 9,8İstismar yokEPSS %119 Mar 2026
- CVE-2026-2288639İzleyin
OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication.
KritikCVSS 9,8İstismar yokEPSS %0eclipse · openmq3 Mar 2026
- CVE-2023-063539İzleyin
Privilege escalation to root
KritikCVSS 9,8İstismar yokEPSS %0abb · aspect-ent-2 firmware5 Haz 2023
- CVE-2025-652338İzleyin
Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenticat
KritikCVSS 9,5İstismar yokEPSS %0devolutions · devolutions server22 Tem 2025
- CVE-2026-807637İzleyin
Weak credentials vulnerability in the CashDro 3 web administration panel
KritikCVSS 9,3İstismar yokEPSS %1cashdro · cashdro 3 administration panel8 May 2026
- CVE-2024-4369837İzleyin
Kieback&Peter DDC4000 Series Use of Weak Credentials
KritikCVSS 9,3İstismar yokEPSS %0kieback&peter · ddc4040e22 Eki 2024
- CVE-2025-3051937İzleyin
Dover Fueling Solutions ProGauge MagLink LX4 Devices Use of Weak Credentials
KritikCVSS 9,3İstismar yokEPSS %0dover fueling solutions · progauge maglink lx 418 Eyl 2025
- CVE-2026-2209437İzleyin
Weak root password in EVbee DC 80
KritikCVSS 9,3İstismar yokevbee · dc 801 gün önce
- CVE-2026-2291036İzleyin
The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized ac
KritikCVSS 9,1İstismar yokEPSS %0sick · tdc-x401gl firmware15 Oca 2026
- CVE-2025-5910336İzleyin
Weak Default Passwords for SSH Access in dormakaba access manager
KritikCVSS 9,2İstismar yokEPSS %0dormakaba · access manager 92xx-k526 Oca 2026
- CVE-2023-4825735İzleyin
The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) wit
YüksekCVSS 8,8İstismar yokEPSS %1bosch · nexo-os10 Oca 2024
- CVE-2024-2907135İzleyin
HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue.
YüksekCVSS 8,8İstismar yokEPSS %0kddi corporation · hgw bl1500hm25 Mar 2024
- CVE-2025-5355834İzleyin
ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K.
YüksekCVSS 8,7Kavram kanıtıEPSS %1zte japan. k.k. · zxhn-f660t31 Tem 2025
- CVE-2026-3508934İzleyin
Use of Weak Credentials in Slican telephone exchanges
YüksekCVSS 8,7İstismar yokEPSS %1slican · ipx27 May 2026
- CVE-2024-4572234İzleyin
Ruijie Reyee OS Use of Weak Credentials
YüksekCVSS 8,7İstismar yokEPSS %0ruijienetworks · reyee os6 Ara 2024
- CVE-2025-3597034İzleyin
On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from the information avail
YüksekCVSS 8,7İstismar yokEPSS %0seiko epson · multiple epson product7 Ağu 2025
- CVE-2024-563434İzleyin
Longse model LBH30FE200W cameras, as well as products based on this device, make use of telnet passwords which follow a specific pattern.
YüksekCVSS 8,6İstismar yokEPSS %0longse technology · lbh30fe200w9 Tem 2024
- CVE-2025-222934İzleyin
Philips Intellispace Cardiovascular (ISCV) Use of Weak Credentials
YüksekCVSS 8,5İstismar yokEPSS %0philips · intellispace cardiovascular (iscv)13 Mar 2025
- GHSA-phh4-3hmm-24rx34İzleyin
Duplicate Advisory: Juju makes Use of Weak Credentials
YüksekCVSS 8,7İstismar yokGo · github.com/juju/juju2 Eki 2024
- CVE-2026-2385333İzleyin
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release ver
YüksekCVSS 8,4İstismar yokEPSS %0dell · powerprotect dp series appliance17 Nis 2026