目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-1392 类漏洞列表 92

CWE-1392 类弱点 92 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-1392 指软件在关键功能中使用默认凭据的漏洞。攻击者常利用公开文档或工具获取这些默认密码,从而绕过身份验证并获取系统控制权。开发者应避免使用硬编码或通用的默认凭据,在部署前强制要求用户修改初始密码,并实施强身份验证机制,确保凭据的唯一性与保密性,以消除此类安全风险。

MITRE CWE 官方描述
CWE:CWE-1392 使用默认凭证 (Use of Default Credentials) 该产品对潜在的关键功能使用了默认凭证 (default credentials)(例如密码或加密密钥)。 产品在设计时采用默认密钥、密码或其他认证机制是一种常见做法。其理由是简化制造流程或系统管理员在企业环境中进行安装和部署的任务。然而,如果管理员未更改这些默认设置,攻击者将更容易在多个组织中快速绕过认证。
常见影响 (1)
AuthenticationGain Privileges or Assume Identity
缓解措施 (3)
RequirementsProhibit use of default, hard-coded, or other values that do not vary for each installation of the product - especially for separate organizations.
Effectiveness: High
Architecture and DesignForce the administrator to change the credential upon installation.
Effectiveness: High
Installation, OperationThe product administrator could change the defaults upon installation or during operation.
Effectiveness: Moderate
代码示例 (1)
In 2022, the OT:ICEFALL study examined products by 10 different Operational Technology (OT) vendors. The researchers reported 56 vulnerabilities and said that the products were "insecure by design" [REF-1283]. If exploited, these vulnerabilities often allowed adversaries to change how the products operated, ranging from denial of service to changing the code that the products executed. Since these…
CVE ID标题CVSS风险等级Published
CVE-2026-68503 LazyOwn:默认C2凭证导致管理访问漏洞 — LazyOwn 9.8 Critical2026-07-30
CVE-2026-41939 Care Everywhere Gateway 信任管理问题漏洞 — Care Everywhere Gateway 9.8 Critical2026-07-29
CVE-2026-44761 SAP Commerce Cloud 信任管理问题漏洞 — SAP Commerce Cloud 9.1 Critical2026-07-14
CVE-2026-3144 IBM API Connect 信任管理问题漏洞 — API Connect 8.1 High2026-07-08
CVE-2026-58466 Estrella Pan AutoBangumi 信任管理问题漏洞 — Auto_Bangumi 9.8 Critical2026-07-02
CVE-2026-58453 JAIOTlink C492A-W6 Wi-Fi IP Camera 信任管理问题漏洞 — C492A-W6 Wi-Fi IP Camera 9.8 Critical2026-07-01
CVE-2026-44273 Dell Wyse Management Suite 信任管理问题漏洞 — Wyse Management Suite (WMS) 6.0 Medium2026-06-22
CVE-2026-32652 Dell AIOps 信任管理问题漏洞 — AIOps 7.8 High2026-06-17
CVE-2026-50005 Brickcom多款产品 安全漏洞 — Cube 7.7 High2026-06-11
CVE-2026-9844 Roche Diagnostics navify Digital Pathology 安全漏洞 — navify Digital Pathology--2026-06-02
CVE-2026-42941 Danelec Marine Danelec MacGregor Voyage Data Recorder 安全漏洞 — MacGregor Voyage Data Recorder (VDR) G4e 8.3 High2026-05-29
CVE-2026-7365 IBM Operations Analytics - Log Analysis 安全漏洞 — Operations Analytics - Log Analysis 8.4 High2026-05-27
CVE-2025-36221 IBM Cloud Pak for Data System 安全漏洞 — Cloud Pak for Data System - Cyclops 5.3 Medium2026-05-26
CVE-2026-44159 Tyler Identity Local 安全漏洞 — TID-L 9.8 Critical2026-05-19
CVE-2026-7428 Google Cloud AlloyDB for PostgreSQL 安全漏洞 — AlloyDB for PostgreSQL--2026-05-12
CVE-2026-42072 NornicDB 安全漏洞 — NornicDB 9.8 Critical2026-05-08
CVE-2023-27573 netbox-docker 安全漏洞 — netbox-docker 9.0 Critical2026-03-11
CVE-2026-28713 Acronis Cyber Protect和Acronis Cyber Protect Cloud Agent 安全漏洞 — Acronis Cyber Protect Cloud Agent 7.8 -2026-03-05
CVE-2026-22886 OpenMQ 安全漏洞 — Eclipse OpenMQ 9.8 Critical2026-03-03
CVE-2026-27751 SODOLA SL902-SWTGW124AS 安全漏洞 — SODOLA SL902-SWTGW124AS 9.8 Critical2026-02-27
CVE-2026-26341 Tattile Smart+ 安全漏洞 — Smart+ 9.8 -2026-02-24
CVE-2026-26366 eNet SMART HOME server 安全漏洞 — eNet SMART HOME server 9.8 Critical2026-02-15
CVE-2025-54756 BrightSign OS 安全漏洞 — BrightSign OS series 4 players 8.4 High2026-02-12
CVE-2026-1972 EDIMAX BR-6208AC 安全漏洞 — BR-6208AC 5.3 Medium2026-02-06
CVE-2026-1803 Ziroom ZHOME A0101 安全漏洞 — ZHOME A0101 8.1 High2026-02-03
CVE-2025-7740 Hitachi SuprOS 安全漏洞 — SuprOS 7.8AIHighAI2026-01-28
CVE-2025-59108 Dormakaba Access Manager 安全漏洞 — Access Manager 92xx-k5 9.8AICriticalAI2026-01-26
CVE-2026-22273 Dell ECS 安全漏洞 — ObjectScale 8.8 High2026-01-23
CVE-2025-58744 Milner ImageDirector Capture 安全漏洞 — ImageDirector Capture 6.2AIMediumAI2026-01-20
CVE-2022-50803 JM-DATA ONU JF511-TV 安全漏洞 — JF511-TV 9.8 Critical2025-12-30

CWE-1392 是常见的弱点类别,本平台收录该类弱点关联的 92 条 CVE 漏洞。