CWE-1392Base

Use of Default Credentials

Incomplete in the CWE catalog · 100 CVEs mapped

100
CVEs mapped
8.6
Median CVSS
What it is

The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

Recent examples
none
CVE-2026-76155

CVE-2026-76155 - UNKNOWN Severity Vulnerability

Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials.

no explanation yet
0%
epss
8.1cvss
CVE-2026-65313

CVE-2026-65313 - HIGH Severity Vulnerability

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.

HIGHno explanation yet
0%
epss
9.8cvss
CVE-2026-68503

CVE-2026-68503 - CRITICAL Severity Vulnerability

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP Basic authentication, allowing any network-reachable attacker who knows the defaults to authenticate to the C2 dashboard with operator-level access. This issue is fixed in 0.2.154.

CRITICALno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1392
Abstraction
Base
Structure
Simple
Status
Incomplete
References (1)