CWE-1391Class

Use of Weak Credentials

Incomplete in the CWE catalog · 46 CVEs mapped

46
CVEs mapped
8.3
Median CVSS
What it is

The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.

Recent examples
8.7cvss
CVE-2026-79679

CVE-2026-79679 - HIGH Severity Vulnerability

Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services. This issue affects mapp Audit used in mapp Services: before 6.8.0.

HIGHno explanation yet
0%
epss
5.3cvss
CVE-2026-66409

CVE-2026-66409 - MEDIUM Severity Vulnerability

DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point of an affected robot.

MEDIUMno explanation yet
0%
epss
4.6cvss
CVE-2026-66408

CVE-2026-66408 - MEDIUM Severity Vulnerability

The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may allow to obtain the password of the root account.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1391
Abstraction
Class
Structure
Simple
Status
Incomplete
References (6)