Vulnerabilities (CVE)

Filtered by CWE-1393
Total 33 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-2347 1 Iroadau 2 Fx2, Fx2 Firmware 2025-11-04 5.8 MEDIUM 6.3 MEDIUM
A vulnerability was found in IROAD Dash Cam FX2 up to 20250308 and classified as problematic. This issue affects some unknown processing of the component Device Registration. The manipulation of the argument Password with the input qwertyuiop leads to use of default password. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used.
CVE-2023-45249 1 Acronis 1 Cyber Infrastructure 2025-10-22 N/A 9.8 CRITICAL
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.
CVE-2025-43021 1 Hp 1 Poly Clariti Manager 2025-10-02 N/A 5.7 MEDIUM
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the use and retrieval of the default password. HP has addressed the issue in the latest software update.
CVE-2024-13966 1 Zkteco 1 Biotime 2025-09-26 N/A 7.3 HIGH
ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should change their passwords (located under the Attendance Settings tab as "Self-Password").
CVE-2025-22938 1 Adtran 2 411, 411 Firmware 2025-08-18 N/A 9.8 CRITICAL
Adtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords.
CVE-2025-2766 1 70mai 2 A510, A510 Firmware 2025-08-18 N/A 8.8 HIGH
70mai A510 Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of 70mai A510. Authentication is not required to exploit this vulnerability. The specific flaw exists within the default configuration of user accounts. The configuration contains default password. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of the root. Was ZDI-CAN-24996.
CVE-2025-27690 1 Dell 1 Powerscale Onefs 2025-07-11 N/A 9.8 CRITICAL
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to the takeover of a high privileged user account.
CVE-2023-24049 1 Connectize 2 Ac21000 G6, Ac21000 G6 Firmware 2025-05-29 N/A 9.8 CRITICAL
An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credential management.
CVE-2024-48987 1 Snipeitapp 1 Snipe-it 2025-05-22 N/A 6.6 MEDIUM
Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.
CVE-2024-49559 1 Dell 1 Smartfabric Os10 2025-04-30 N/A 8.8 HIGH
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
CVE-2025-2921 1 Netis-systems 2 Netis Wf-2404, Netis Wf-2404 Firmware 2025-04-17 6.2 MEDIUM 6.4 MEDIUM
A vulnerability classified as critical has been found in Netis WF-2404 1.1.124EN. Affected is an unknown function of the file /etc/passwd. The manipulation with the input Realtek leads to use of default password. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-1878 1 I-drive 4 I11, I11 Firmware, I12 and 1 more 2025-03-06 1.8 LOW 3.1 LOW
A vulnerability has been found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This vulnerability affects unknown code of the component WiFi. The manipulation leads to use of default password. Access to the local network is required for this attack to succeed. The complexity of an attack is rather high. The exploitation appears to be difficult. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.
CVE-2023-43042 1 Ibm 1 Storage Virtualize 2024-11-21 N/A 7.5 HIGH
IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.3 products use default passwords for a privileged user. IBM X-Force ID: 266874.