<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Default Credentials (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/default-cred.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/default-cred-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Default Credentials (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:34 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-9844 – Use of default credentials vulnerability in Roche Diagnostics navify Digital Pat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9844</guid>
    <pubDate>Tue, 02 Jun 2026 14:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9844</strong></p>
  <p>Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Passwords. This issue affects navify Digital Pathology: from 2.0.0 before 2.4.1.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44825 – Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44825</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44825</strong></p>
  <p>Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account.   As an immediate workaround without upgrading, delete the template users (superadmin, a…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7365 – IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Anal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7365</guid>
    <pubDate>Wed, 27 May 2026 14:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7365</strong></p>
  <p>IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37220 – Huawei HG630 V2 router contains an authentication bypass vulnerability that allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37220</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37220</guid>
    <pubDate>Wed, 13 May 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37220</strong></p>
  <p>Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can query the /api/system/deviceinfo endpoint without authentication to extract the SerialNumber field, then use the last 8 characters as the default password to log in to the router.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37220">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7428 – Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Clo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7428</guid>
    <pubDate>Tue, 12 May 2026 10:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7428</strong></p>
  <p>Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could have been exploited by a remote attacker to gain full administrative access to the database.     Exploitation required network access to the AlloyDB cluster and was limited to Terraform or the REST API, as other clients…</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39920 – BridgeHead FileStore versions prior to 24A (released in early 2024) expose the A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39920</guid>
    <pubDate>Fri, 24 Apr 2026 16:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39920</strong></p>
  <p>BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default credentials, upload a malicious Java archive as a web service, and execute arbitrary co…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39462 – A vulnerability exists in SenseLive X3050’s web management interface in which pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39462</guid>
    <pubDate>Fri, 24 Apr 2026 00:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39462</strong></p>
  <p>A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied due to improper handling of credential changes on the backend. After the device undergoes a factory restore using the SenseLive Config 2.0 tool, the interface may indicate that the password update was successful; however, the system may continue to accept the previous or default…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33707 – Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33707</guid>
    <pubDate>Fri, 10 Apr 2026 19:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33707</strong></p>
  <p>Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email can compute the reset token and change the victim's password without authentication. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33784 – A Use of Default Password vulnerability in the Juniper Networks 

Support Insigh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33784</guid>
    <pubDate>Thu, 09 Apr 2026 22:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33784</strong></p>
  <p>A Use of Default Password vulnerability in the Juniper Networks   Support Insights (JSI)   Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device.  vLWC software images ship with an initial password for a high privileged account. A change of this password is not enforced during the provisioning of the software, which can make full…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4404 – Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4404</guid>
    <pubDate>Mon, 23 Mar 2026 15:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4404</strong></p>
  <p>Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-27573 – netbox-docker before 2.5.0 has a superuser account with default credentials (adm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27573</guid>
    <pubDate>Wed, 11 Mar 2026 06:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-27573</strong></p>
  <p>netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SUPERUSER_API_TOKEN). In practice on the public Internet, almost all users changed the password but only about 90% changed the token. Having a default token value was intentional and was valuable for the main intended use case of…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28713 – Default credentials set for local privileged user in Virtual Appliance. The foll...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28713</guid>
    <pubDate>Fri, 06 Mar 2026 00:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28713</strong></p>
  <p>Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyber Protect Cloud Agent (VMware) before build 36943, Acronis Cyber Protect 17 (VMware) before build 41186.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-22886 – OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22886</guid>
    <pubDate>Tue, 03 Mar 2026 10:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-22886</strong></p>
  <p>OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login, the server continues to accept the default password indefinitely without warning or enforcement.   In real-world deploymen…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1391</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27751 – SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default cre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27751</guid>
    <pubDate>Fri, 27 Feb 2026 18:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27751</strong></p>
  <p>SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attackers can authenticate using the hardcoded default credentials without password change enforcement to gain full administrative control of the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26341 – Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26341</guid>
    <pubDate>Tue, 24 Feb 2026 20:27:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26341</strong></p>
  <p>Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain administrative access, enabling unauthorized access to device configuration and data.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13776 – Multiple Finka programs use hard-coded Firebird database credentials (shared acr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13776</guid>
    <pubDate>Tue, 24 Feb 2026 17:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13776</strong></p>
  <p>Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local network who knows default credentials is able to read and edit database content.  This vulnerability has been fixed in version: Finka-FK 18.5, Finka-KPR 16.6, Finka-Płace 13.4, Finka-Faktura 18.3, Finka-Magazyn 8.3, Finka-STW 12.3</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-2635 – MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2635</guid>
    <pubDate>Fri, 20 Feb 2026 23:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-2635</strong></p>
  <p>MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability.  The specific flaw exists within the basic_auth.ini file. The file contains hard-coded default credentials. An attacker can leverage this vulnerability to bypass au…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-70998 – UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70998</guid>
    <pubDate>Wed, 18 Feb 2026 16:22:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-70998</strong></p>
  <p>UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the telnet service, possibly allowing a remote attacker to gain root access via a crafted script.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26366 – eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26366</guid>
    <pubDate>Sun, 15 Feb 2026 16:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26366</strong></p>
  <p>eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Unauthenticated attackers can use these default credentials to gain administrative access to sensitive smart home configuration and control functions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26218 – newbee-mall includes pre-seeded administrator accounts in its database initializ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26218</guid>
    <pubDate>Thu, 12 Feb 2026 19:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26218</strong></p>
  <p>newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may allow unauthenticated attackers to log in as an administrator and gain full administrative control…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54756 – BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or 
series ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54756</guid>
    <pubDate>Thu, 12 Feb 2026 17:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54756</strong></p>
  <p>BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or  series 5 prior to v9.0.166 use a default password that is guessable with  knowledge of the device information. The latest release fixes this  issue for new installations; users of old installations are encouraged  to change all default passwords.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-25803 – 3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25803</guid>
    <pubDate>Fri, 06 Feb 2026 23:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-25803</strong></p>
  <p>3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network access to the application's login interface can gain full administrative control, managing VPN tunnels and system settings. This issue will be patched in version…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-25753 – PlaciPy is a placement management system designed for educational institutions. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25753</guid>
    <pubDate>Fri, 06 Feb 2026 19:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-25753</strong></p>
  <p>PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass account takeover, allowing any attacker to log in as any student once the password is known.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1803 – A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1803</guid>
    <pubDate>Tue, 03 Feb 2026 20:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1803</strong></p>
  <p>A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes use of default credentials. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been made available to the public and could be used for attack…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7740 – Default credentials vulnerability exists in SuprOS
product. If exploited, this c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7740</guid>
    <pubDate>Wed, 28 Jan 2026 09:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7740</strong></p>
  <p>Default credentials vulnerability exists in SuprOS product. If exploited, this could allow an authenticated local attacker to use an admin account created during product deployment.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24346 – Use of well-known default credentials in Admin UI of EZCast Pro II version 1.174...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24346</guid>
    <pubDate>Tue, 27 Jan 2026 10:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24346</strong></p>
  <p>Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web application</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24429 – Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24429</guid>
    <pubDate>Mon, 26 Jan 2026 18:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24429</strong></p>
  <p>Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial configuration. An attacker can leverage these default credentials to gain authenticated access to the management interface.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22273 – Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22273</guid>
    <pubDate>Fri, 23 Jan 2026 10:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22273</strong></p>
  <p>Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default Credentials vulnerability in the OS. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58744 – Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58744</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58744</strong></p>
  <p>Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in    Milner ImageDirector Capture on Windows allows decryption of document archive files using credentials decrypted with hard-coded application encryption key.  This issue affects ImageDirector Capture: from 7.0.9.0 before 7.6.3.25808.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-47796 – Denver SHC-150 Smart Wifi Camera contains a hardcoded telnet credential vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47796</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47796</guid>
    <pubDate>Fri, 16 Jan 2026 00:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-47796</strong></p>
  <p>Denver SHC-150 Smart Wifi Camera contains a hardcoded telnet credential vulnerability that allows unauthenticated attackers to access a Linux shell. Attackers can connect to port 23 using the default credential to execute arbitrary commands on the camera's operating system.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47796">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22910 – The device is deployed with weak and publicly known default passwords for certai...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22910</guid>
    <pubDate>Thu, 15 Jan 2026 13:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22910</strong></p>
  <p>The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1391</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25289 – SmartLiving SmartLAN &lt;=6.x contains an authenticated remote command injection vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25289</guid>
    <pubDate>Thu, 08 Jan 2026 00:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25289</strong></p>
  <p>SmartLiving SmartLAN <=6.x contains an authenticated remote command injection vulnerability in the web.cgi binary through the 'par' POST parameter with the 'testemail' module. Attackers can exploit the unsanitized parameter and system() function call to execute arbitrary system commands with root privileges using default credentials.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36915 – Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36915</guid>
    <pubDate>Tue, 06 Jan 2026 16:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36915</strong></p>
  <p>Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials to gain root-level access and execute system commands across multiple Adtec Digital product versions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36910 – Cayin Signage Media Player 3.0 contains an authenticated remote command injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36910</guid>
    <pubDate>Tue, 06 Jan 2026 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36910</strong></p>
  <p>Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-15111 – Ksenia Security lares (legacy model) version 1.6 contains a default credentials ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15111</guid>
    <pubDate>Tue, 30 Dec 2025 23:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-15111</strong></p>
  <p>Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploit the weak default administrative credentials to obtain full control of the home automation system.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-50803 – JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50803</guid>
    <pubDate>Tue, 30 Dec 2025 23:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-50803</strong></p>
  <p>JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the device with administrative privileges.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25147 – Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25147</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25147</guid>
    <pubDate>Wed, 24 Dec 2025 20:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25147</strong></p>
  <p>Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to the device by logging in with predefined username and password combinations.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25147">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-67418 – ClipBucket 5.5.2 is affected by an improper access control issue where the produ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67418</guid>
    <pubDate>Mon, 22 Dec 2025 20:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-67418</strong></p>
  <p>ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative credentials. An unauthenticated remote attacker can log in to the administrative panel using these default credentials, resulting in full administrative control of the application.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-56157 – Default credentials in Dify thru 1.5.1. PostgreSQL username and password specifi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-56157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-56157</guid>
    <pubDate>Thu, 18 Dec 2025 19:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-56157</strong></p>
  <p>Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-13955 – Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13955</guid>
    <pubDate>Wed, 10 Dec 2025 09:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-13955</strong></p>
  <p>Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II before version 1.17478.177 allows attackers in Wi-Fi range to gain access to the dongle by calculating the default password from observable device identifiers</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54303 – The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default crede...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54303</guid>
    <pubDate>Thu, 04 Dec 2025 15:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54303</strong></p>
  <p>The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The ionadmin user account can be used to authenticate to default deployments with the password ionadmin. The user guide recommends changing default credentials; however, a password change policy for default administrative accounts is not enforced. Many deplo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-53963 – An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53963</guid>
    <pubDate>Thu, 04 Dec 2025 15:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-53963</strong></p>
  <p>An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The root account has a weak default password of ionadmin, and a password change policy for the root account is not enforced. Thus, an attacker with network connectivity can achieve root code execution. NOTE: This vulnerability only affects products that a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-63353 – A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63353</guid>
    <pubDate>Wed, 12 Nov 2025 16:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-63353</strong></p>
  <p>A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID. The device generates default passwords using a deterministic algorithm that derives the router passphrase from the SSID, enabling an attacker who can observe the SSID to predict the default password without authentication or user interac…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12218 – Weak Default Credentials.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12218</guid>
    <pubDate>Sat, 25 Oct 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12218</strong></p>
  <p>Weak Default Credentials.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41719 – A low privileged remote attacker can corrupt the webserver users storage on the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41719</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41719</guid>
    <pubDate>Wed, 22 Oct 2025 07:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41719</strong></p>
  <p>A low privileged remote attacker can corrupt the webserver users storage on the device by setting a sequence of unsupported characters which leads to deletion of all previously configured users and the creation of the default Administrator with a known default password.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1286</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41719">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-10678 – NetBird VPN when installed using vendor's provided script failed to remove or ch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10678</guid>
    <pubDate>Mon, 20 Oct 2025 16:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-10678</strong></p>
  <p>NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL. This issue affects instances installed using vendor's provided script. This issue may affect instances created with Docker if the default password was not changed nor the user was removed.  This issue has been fixed in version 0.57.0</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11943 – A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11943</guid>
    <pubDate>Sun, 19 Oct 2025 20:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11943</strong></p>
  <p>A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality of the component HTTP Web Server. The manipulation leads to use of default credentials. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34516 – Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34516</guid>
    <pubDate>Thu, 16 Oct 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34516</strong></p>
  <p>Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34223 – Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34223</guid>
    <pubDate>Mon, 29 Sep 2025 21:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34223</strong></p>
  <p>Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) contain a default admin account and an installation‑time endpoint at `/admin/query/update_database.php` that can be accessed without authentication. An attacker who can reach the installation web interface can POST arbitrary `root_user` and `root_…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10957 – This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10957</guid>
    <pubDate>Thu, 25 Sep 2025 12:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10957</strong></p>
  <p>This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. A remote attacker could exploit this vulnerability by establishing an FTP connection using default credentials, potentially gaining unauthorized access to configuration files, user credentials, or other sensitive information stored on the targeted device.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57295 – H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57295</guid>
    <pubDate>Thu, 18 Sep 2025 21:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57295</strong></p>
  <p>H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user account has no password set, and the H3C user account uses the default password "admin," both stored in the /etc/shadow file. Attackers with network access can exploit these credentials to gain unauthorized root-level access to the device via the administrativ…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-8077 – A vulnerability exists in NeuVector versions up to and including 5.4.5, where a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8077</guid>
    <pubDate>Wed, 17 Sep 2025 13:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-8077</strong></p>
  <p>A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default password for the built-in `admin` account. If this password is not changed immediately after deployment, any workload with network access within the cluster could use the default credentials to obtain an authentication token. This token can then be used to perform any operation via…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57579 – An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57579</guid>
    <pubDate>Fri, 12 Sep 2025 16:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57579</strong></p>
  <p>An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57578 – An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57578</guid>
    <pubDate>Fri, 12 Sep 2025 16:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57578</strong></p>
  <p>An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57577 – An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57577</guid>
    <pubDate>Fri, 12 Sep 2025 16:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57577</strong></p>
  <p>An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's position is that their "product lines enforce or clearly prompt users to change any initial credentials upon first use. At most, this would be a case of misconfiguration if an administrator deliberately ignored the prompts, which is outside the scope of CVE definit…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57577">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55051 – CWE-1392: Use of Default Credentials</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55051</guid>
    <pubDate>Tue, 09 Sep 2025 19:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55051</strong></p>
  <p>CWE-1392: Use of Default Credentials</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-10062 – A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-10062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-10062</guid>
    <pubDate>Sat, 30 Aug 2025 14:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-10062</strong></p>
  <p>A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload and execute arbitrary PHP code. The WebDAV service, accessible via /webdav/, accepts HTTP PUT requests using default credentials. This permits attackers to upload a malicious PHP payload and trigger its execution via a subsequent GET request, resultin…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-10062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-35114 – Agiloft Release 28 contains several accounts with default credentials that could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-35114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-35114</guid>
    <pubDate>Tue, 26 Aug 2025 23:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-35114</strong></p>
  <p>Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The password hash is known for at least one of the accounts and the credentials could be cracked offline. Users should upgrade to Agiloft Release 30.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-35114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7342 – A security issue was discovered in the Kubernetes Image Builder where default cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7342</guid>
    <pubDate>Sun, 17 Aug 2025 23:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7342</strong></p>
  <p>A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the Windows image build process when using the Nutanix or VMware OVA providers. These credentials, which allow root access, are disabled at the conclusion of the build. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project and the vulnerab…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-10056 – PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-10056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-10056</guid>
    <pubDate>Wed, 13 Aug 2025 21:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-10056</strong></p>
  <p>PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnerability in its document upload functionality. Authenticated users can upload files to the mods/documents/uploads/ directory without any restriction on file type or extension. Because this directory is publicly accessible and lacks execution controls, attackers can upload a malicious PHP payload and execute it remotely.…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-10056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-10042 – Sflog! CMS 1.0 contains an authenticated arbitrary file upload vulnerability in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-10042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-10042</guid>
    <pubDate>Fri, 08 Aug 2025 19:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-10042</strong></p>
  <p>Sflog! CMS 1.0 contains an authenticated arbitrary file upload vulnerability in the blog management interface. The application ships with default credentials (admin:secret) and allows authenticated users to upload files via manage.php. The upload mechanism fails to validate file types, enabling attackers to upload a PHP backdoor into a web-accessible directory (blogs/download/uploads/). Once uplo…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-10042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-8731 – A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8731</guid>
    <pubDate>Fri, 08 Aug 2025 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-8731</strong></p>
  <p>A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown part of the component SSH Service. The manipulation leads to use of default credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7769 – Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7769</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7769</guid>
    <pubDate>Wed, 06 Aug 2025 21:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7769</strong></p>
  <p>Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due to improper handling of user input. When used with default credentials, this enables attackers to execute arbitrary commands on the device that could cause potential unauthorized access, service disruption, and data exp…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7769">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-10059 – An authenticated OS command injection vulnerability exists in various D-Link rou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-10059</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-10059</guid>
    <pubDate>Fri, 01 Aug 2025 21:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-10059</strong></p>
  <p>An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmware version 8.04) via the tools_vct.htm endpoint. The web interface fails to sanitize input passed from the ping_ipaddr parameter to the tools_vct.htm diagnostic interface, allowing attackers to inject arbitrary shell commands using backtick encapsulation. With default credential…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-10059">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30125 – An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30125</guid>
    <pubDate>Mon, 28 Jul 2025 15:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30125</strong></p>
  <p>An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which creates an insecure-by-default condition. For users who change their passwords, it's limited to 8 characters. These short passwords can be cracked in 8 hours via low-end commercial cloud resources.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30133 – An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30133</guid>
    <pubDate>Mon, 28 Jul 2025 14:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30133</strong></p>
  <p>An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IROAD X View" app for authentication, but its HTTP server lacks this restriction. Once connected to the dashcam's Wi-Fi network via the default password ("qwertyuiop"), an attacker can directly access the HTTP server at http://192.168.10.1 without undergo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-29629 – Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29629</guid>
    <pubDate>Fri, 25 Jul 2025 17:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-29629</strong></p>
  <p>Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54137 – HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS bac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54137</guid>
    <pubDate>Tue, 22 Jul 2025 22:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54137</strong></p>
  <p>HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend. Versions 11.0.9 and below were distributed with hardcoded default credentials for the user and superuser accounts. Additionally, the application has default private keys for JWTs. Users aren't prompted to change credentials or secrets during installation, and there is no way to change them through the UI. An una…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-7503 – An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7503</guid>
    <pubDate>Fri, 11 Jul 2025 19:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-7503</strong></p>
  <p>An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet service (port 23) with undocumented, default credentials. The Telnet service is enabled by default and is not disclosed or configurable via the device’s web interface or user manual. An attacker with network access can authenticate using default credentials and gain root-level shell access to the devi…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34058 – Hikvision Streaming Media Management Server v2.3.5 uses default credentials that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34058</guid>
    <pubDate>Tue, 01 Jul 2025 15:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34058</strong></p>
  <p>Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary file read vulnerability in the /systemLog/downFile.php endpoint via directory traversal in the fileName parameter. This exploit chain can enable unauthorized ac…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6529 – A vulnerability was found in 70mai M300 up to 20250611 and classified as critica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6529</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6529</guid>
    <pubDate>Mon, 23 Jun 2025 23:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6529</strong></p>
  <p>A vulnerability was found in 70mai M300 up to 20250611 and classified as critical. Affected by this issue is some unknown functionality of the component Telnet Service. The manipulation leads to use of default credentials. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure bu…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6529">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-24288 – The Versa Director software exposes a number of services by default and allow at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24288</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24288</guid>
    <pubDate>Thu, 19 Jun 2025 00:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-24288</strong></p>
  <p>The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes ssh and postgres to the internet, alongside a host of other services.  Versa Networks is not aware of any reported instance where this vulner…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24288">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5484 – A username and password are required to authenticate to the central 
SinoTrack d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5484</guid>
    <pubDate>Thu, 12 Jun 2025 20:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5484</strong></p>
  <p>A username and password are required to authenticate to the central  SinoTrack device management interface. The username for all devices is  an identifier printed on the receiver. The default password is  well-known and common to all devices. Modification of the default  password is not enforced during device setup. A malicious actor can  retrieve device identifiers with either physical access or…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-1390</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-40585 – A vulnerability has been identified in Energy Services (All versions with G5DFR)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40585</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40585</guid>
    <pubDate>Tue, 10 Jun 2025 16:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-40585</strong></p>
  <p>A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain default credentials. This could allow an attacker to gain control of G5DFR component and tamper with outputs from the device.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40585">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46612 – The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46612</guid>
    <pubDate>Tue, 10 Jun 2025 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46612</strong></p>
  <p>The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary commands via a wizard/workspace.jsp unrestricted file upload. To exploit this, the attacker must login to the administrator console (default credentials are weak and easily guessable) and upload a JSP file via the Panel Designer dashboard.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2766 – 70mai A510 Use of Default Password Authentication Bypass Vulnerability. This vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2766</guid>
    <pubDate>Fri, 06 Jun 2025 19:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2766</strong></p>
  <p>70mai A510 Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of 70mai A510. Authentication is not required to exploit this vulnerability.  The specific flaw exists within the default configuration of user accounts. The configuration contains default password. An attacker can leverage…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5124 – A vulnerability classified as critical has been found in Sony SNC-M1, SNC-M3, SN...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5124</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5124</guid>
    <pubDate>Sat, 24 May 2025 13:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5124</strong></p>
  <p>A vulnerability classified as critical has been found in Sony SNC-M1, SNC-M3, SNC-RZ25N, SNC-RZ30N, SNC-DS10, SNC-CS3N and SNC-RX570N up to 1.30. This affects an unknown part of the component Administrative Interface. The manipulation leads to use of default credentials. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be di…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5124">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-5058 – The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5058</guid>
    <pubDate>Sat, 24 May 2025 04:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-5058</strong></p>
  <p>The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_image() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This is only exploitable by u…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-4603 – The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4603</guid>
    <pubDate>Sat, 24 May 2025 04:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-4603</strong></p>
  <p>The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4336 – The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4336</guid>
    <pubDate>Sat, 24 May 2025 04:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4336</strong></p>
  <p>The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_file() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This is only exploitable by un…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22460 – Default credentials in Ivanti Cloud Services Application before version 5.0.5 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22460</guid>
    <pubDate>Tue, 13 May 2025 15:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22460</strong></p>
  <p>Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-28200 – Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default pas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-28200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-28200</guid>
    <pubDate>Fri, 09 May 2025 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-28200</strong></p>
  <p>Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-28200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-27690 – Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of defa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27690</guid>
    <pubDate>Thu, 10 Apr 2025 03:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-27690</strong></p>
  <p>Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to the takeover of a high privileged user account.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-22938 – Adtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22938</guid>
    <pubDate>Mon, 31 Mar 2025 15:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-22938</strong></p>
  <p>Adtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30118 – An issue was discovered on the Audi Universal Traffic Recorder 2.88. It has Susc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30118</guid>
    <pubDate>Tue, 25 Mar 2025 20:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30118</strong></p>
  <p>An issue was discovered on the Audi Universal Traffic Recorder 2.88. It has Susceptibility to denial of service. It uses the same default credentials for all devices and does not implement proper multi-device authentication, allowing attackers to deny the owner access by occupying the only available connection. The SSID remains broadcast at all times, increasing exposure to potential attacks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30139 – An issue was discovered on G-Net Dashcam BB GONX devices. Default credentials fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30139</guid>
    <pubDate>Tue, 18 Mar 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30139</strong></p>
  <p>An issue was discovered on G-Net Dashcam BB GONX devices. Default credentials for SSID cannot be changed. It broadcasts a fixed SSID with default credentials that cannot be changed. This allows any nearby attacker to connect to the dashcam's network without restriction. Once connected, an attacker can sniff on connected devices such as the user's smartphone. The SSID is also always broadcasted.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30122 – An issue was discovered on ROADCAM X3 devices. It has a uniform default credenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30122</guid>
    <pubDate>Tue, 18 Mar 2025 15:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30122</strong></p>
  <p>An issue was discovered on ROADCAM X3 devices. It has a uniform default credential set that cannot be modified by users, making it easy for attackers to gain unauthorized access to multiple devices.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30115 – An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Defau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30115</guid>
    <pubDate>Tue, 18 Mar 2025 15:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30115</strong></p>
  <p>An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Default Credentials Cannot Be Changed. It uses a fixed default SSID and password ("qwertyuiop"), which cannot be modified by users. The SSID is continuously broadcast, allowing unauthorized access to the device network.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30106 – On IROAD v9 devices, the dashcam has hardcoded default credentials ("qwertyuiop"...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30106</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30106</guid>
    <pubDate>Tue, 18 Mar 2025 14:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30106</strong></p>
  <p>On IROAD v9 devices, the dashcam has hardcoded default credentials ("qwertyuiop") that cannot be changed by the user. This allows an attacker within Wi-Fi range to connect to the device's network to perform sniffing.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30106">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2398 – A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2398</guid>
    <pubDate>Mon, 17 Mar 2025 22:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2398</strong></p>
  <p>A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been rated as critical. This issue affects some unknown processing of the component CLI su Command Handler. The manipulation leads to use of default credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. T…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49559 – Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49559</guid>
    <pubDate>Mon, 17 Mar 2025 18:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49559</strong></p>
  <p>Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-1960 – CWE-1188: Initialization of a Resource with an Insecure Default vulnerability ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1960</guid>
    <pubDate>Wed, 12 Mar 2025 16:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-1960</strong></p>
  <p>CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an attacker to execute unauthorized commands when a system’s default password credentials have not been changed on first use. The default username is not displayed correctly in the WebHMI interface.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-26793 – The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26793</guid>
    <pubDate>Sat, 15 Feb 2025 15:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-26793</strong></p>
  <p>The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not prompted to change these credentials on initial configuration, and changing the credentials requires many steps. Attackers can use the credentials over the Internet via mesh.webadmin.MESHAdminServlet t…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-12013 – A CWE-1392 “Use of Default Credentials” was discovered affecting the 130.8005 TC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-12013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-12013</guid>
    <pubDate>Thu, 13 Feb 2025 16:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-12013</strong></p>
  <p>A CWE-1392 “Use of Default Credentials” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The device exposes an FTP server with default and easy-to-guess admin credentials. A remote attacker capable of interacting with the FTP server could gain access and perform changes over resources exposed by the service such as configuration files where password hashes are sa…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-54015 – A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions &lt; ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54015</guid>
    <pubDate>Tue, 11 Feb 2025 11:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-54015</strong></p>
  <p>A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 6MD86 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 6MD89 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 6MD89 (CP300) V9.6x (All versions < V9.68), SIPROTEC 5 6MU85 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7KE85 (CP300)…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1160 – A vulnerability was found in SourceCodester Employee Management System 1.0. It h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1160</guid>
    <pubDate>Mon, 10 Feb 2025 23:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1160</strong></p>
  <p>A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument username/password leads to use of default credentials. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46433 – A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46433</guid>
    <pubDate>Mon, 10 Feb 2025 19:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46433</strong></p>
  <p>A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using the default rzadmin account with administrative privileges.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-0890 – **UNSUPPORTED WHEN ASSIGNED**
Insecure default credentials for the Telnet functi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0890</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0890</guid>
    <pubDate>Tue, 04 Feb 2025 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-0890</strong></p>
  <p>**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0890">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-3365 – Due to reliance on a trivial substitution cipher, sent in cleartext, and the rel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3365</guid>
    <pubDate>Tue, 28 Jan 2025 01:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-3365</strong></p>
  <p>Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be abused by attackers to inject OS commands over theproduct's custom control protocol. A Metasploit module was written and tested against version 4.110, the current version when this CVE was reserved.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23012 – Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with defa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23012</guid>
    <pubDate>Thu, 23 Jan 2025 21:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23012</strong></p>
  <p>Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with default credentials and privileges to read read local files by manipulating datastreams. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23012">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
