<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Default Credentials</title>
  <link>https://cvedaily.com/pages/tags/default-cred.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/default-cred.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Default Credentials</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:34 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-9844 – Use of default credentials vulnerability in Roche Diagnostics navify Digital Pat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9844</guid>
    <pubDate>Tue, 02 Jun 2026 14:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9844</strong></p>
  <p>Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Passwords. This issue affects navify Digital Pathology: from 2.0.0 before 2.4.1.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44825 – Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44825</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44825</strong></p>
  <p>Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account.   As an immediate workaround without upgrading, delete the template users (superadmin, a…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4377 – Dlink DWR-X1820 router uses weak default password generated from its IMEI number...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4377</guid>
    <pubDate>Thu, 28 May 2026 10:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4377</strong></p>
  <p>Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. An attacker who knows how passwords are generated can easily crack the default password if they have the device IMEI number.  This issue was fixed in version 1.00B16CP.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-1391</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7365 – IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Anal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7365</guid>
    <pubDate>Wed, 27 May 2026 14:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7365</strong></p>
  <p>IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36221 – IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through  Interim Fix 002 IBM Cl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36221</guid>
    <pubDate>Tue, 26 May 2026 17:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36221</strong></p>
  <p>IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through  Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8672 – Use of default password vulnerability in syslink software AG Avantra on Linux, W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8672</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8672</guid>
    <pubDate>Fri, 22 May 2026 14:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8672</strong></p>
  <p>Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default Usernames and Passwords.  This issue affects Avantra: before 25.3.0.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8672">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-8803 – A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8803</guid>
    <pubDate>Mon, 18 May 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-8803</strong></p>
  <p>A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation causes use of weak hash. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitability is considered difficult. The actual existence of this vulnerab…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37220 – Huawei HG630 V2 router contains an authentication bypass vulnerability that allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37220</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37220</guid>
    <pubDate>Wed, 13 May 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37220</strong></p>
  <p>Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can query the /api/system/deviceinfo endpoint without authentication to extract the SerialNumber field, then use the last 8 characters as the default password to log in to the router.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37220">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7428 – Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Clo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7428</guid>
    <pubDate>Tue, 12 May 2026 10:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7428</strong></p>
  <p>Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could have been exploited by a remote attacker to gain full administrative access to the database.     Exploitation required network access to the AlloyDB cluster and was limited to Terraform or the REST API, as other clients…</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39920 – BridgeHead FileStore versions prior to 24A (released in early 2024) expose the A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39920</guid>
    <pubDate>Fri, 24 Apr 2026 16:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39920</strong></p>
  <p>BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default credentials, upload a malicious Java archive as a web service, and execute arbitrary co…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39462 – A vulnerability exists in SenseLive X3050’s web management interface in which pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39462</guid>
    <pubDate>Fri, 24 Apr 2026 00:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39462</strong></p>
  <p>A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied due to improper handling of credential changes on the backend. After the device undergoes a factory restore using the SenseLive Config 2.0 tool, the interface may indicate that the password update was successful; however, the system may continue to accept the previous or default…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33707 – Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33707</guid>
    <pubDate>Fri, 10 Apr 2026 19:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33707</strong></p>
  <p>Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email can compute the reset token and change the victim's password without authentication. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33784 – A Use of Default Password vulnerability in the Juniper Networks 

Support Insigh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33784</guid>
    <pubDate>Thu, 09 Apr 2026 22:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33784</strong></p>
  <p>A Use of Default Password vulnerability in the Juniper Networks   Support Insights (JSI)   Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device.  vLWC software images ship with an initial password for a high privileged account. A change of this password is not enforced during the provisioning of the software, which can make full…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4404 – Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4404</guid>
    <pubDate>Mon, 23 Mar 2026 15:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4404</strong></p>
  <p>Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-27573 – netbox-docker before 2.5.0 has a superuser account with default credentials (adm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27573</guid>
    <pubDate>Wed, 11 Mar 2026 06:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-27573</strong></p>
  <p>netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SUPERUSER_API_TOKEN). In practice on the public Internet, almost all users changed the password but only about 90% changed the token. Having a default token value was intentional and was valuable for the main intended use case of…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28713 – Default credentials set for local privileged user in Virtual Appliance. The foll...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28713</guid>
    <pubDate>Fri, 06 Mar 2026 00:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28713</strong></p>
  <p>Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyber Protect Cloud Agent (VMware) before build 36943, Acronis Cyber Protect 17 (VMware) before build 41186.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-22886 – OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22886</guid>
    <pubDate>Tue, 03 Mar 2026 10:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-22886</strong></p>
  <p>OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login, the server continues to accept the default password indefinitely without warning or enforcement.   In real-world deploymen…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1391</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27751 – SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default cre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27751</guid>
    <pubDate>Fri, 27 Feb 2026 18:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27751</strong></p>
  <p>SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attackers can authenticate using the hardcoded default credentials without password change enforcement to gain full administrative control of the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3186 – A vulnerability was determined in feiyuchuixue sz-boot-parent up to 1.3.2-beta. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3186</guid>
    <pubDate>Wed, 25 Feb 2026 14:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3186</strong></p>
  <p>A vulnerability was determined in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this vulnerability is an unknown functionality of the file /api/admin/sys-user/reset/password/ of the component Password Reset Handler. This manipulation of the argument userId causes use of default password. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26341 – Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26341</guid>
    <pubDate>Tue, 24 Feb 2026 20:27:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26341</strong></p>
  <p>Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain administrative access, enabling unauthorized access to device configuration and data.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13776 – Multiple Finka programs use hard-coded Firebird database credentials (shared acr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13776</guid>
    <pubDate>Tue, 24 Feb 2026 17:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13776</strong></p>
  <p>Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local network who knows default credentials is able to read and edit database content.  This vulnerability has been fixed in version: Finka-FK 18.5, Finka-KPR 16.6, Finka-Płace 13.4, Finka-Faktura 18.3, Finka-Magazyn 8.3, Finka-STW 12.3</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-2635 – MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2635</guid>
    <pubDate>Fri, 20 Feb 2026 23:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-2635</strong></p>
  <p>MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability.  The specific flaw exists within the basic_auth.ini file. The file contains hard-coded default credentials. An attacker can leverage this vulnerability to bypass au…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-70998 – UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70998</guid>
    <pubDate>Wed, 18 Feb 2026 16:22:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-70998</strong></p>
  <p>UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the telnet service, possibly allowing a remote attacker to gain root access via a crafted script.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26366 – eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26366</guid>
    <pubDate>Sun, 15 Feb 2026 16:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26366</strong></p>
  <p>eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Unauthenticated attackers can use these default credentials to gain administrative access to sensitive smart home configuration and control functions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26218 – newbee-mall includes pre-seeded administrator accounts in its database initializ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26218</guid>
    <pubDate>Thu, 12 Feb 2026 19:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26218</strong></p>
  <p>newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may allow unauthenticated attackers to log in as an administrator and gain full administrative control…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54756 – BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or 
series ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54756</guid>
    <pubDate>Thu, 12 Feb 2026 17:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54756</strong></p>
  <p>BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or  series 5 prior to v9.0.166 use a default password that is guessable with  knowledge of the device information. The latest release fixes this  issue for new installations; users of old installations are encouraged  to change all default passwords.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-25803 – 3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25803</guid>
    <pubDate>Fri, 06 Feb 2026 23:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-25803</strong></p>
  <p>3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network access to the application's login interface can gain full administrative control, managing VPN tunnels and system settings. This issue will be patched in version…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-25753 – PlaciPy is a placement management system designed for educational institutions. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25753</guid>
    <pubDate>Fri, 06 Feb 2026 19:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-25753</strong></p>
  <p>PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass account takeover, allowing any attacker to log in as any student once the password is known.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1972 – A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1972</guid>
    <pubDate>Fri, 06 Feb 2026 02:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1972</strong></p>
  <p>A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Performing a manipulation of the argument Username/Password results in use of default credentials. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor confirms that the affected product is end-of-life. They confirm that they "will issue…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1803 – A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1803</guid>
    <pubDate>Tue, 03 Feb 2026 20:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1803</strong></p>
  <p>A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes use of default credentials. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been made available to the public and could be used for attack…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7740 – Default credentials vulnerability exists in SuprOS
product. If exploited, this c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7740</guid>
    <pubDate>Wed, 28 Jan 2026 09:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7740</strong></p>
  <p>Default credentials vulnerability exists in SuprOS product. If exploited, this could allow an authenticated local attacker to use an admin account created during product deployment.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24346 – Use of well-known default credentials in Admin UI of EZCast Pro II version 1.174...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24346</guid>
    <pubDate>Tue, 27 Jan 2026 10:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24346</strong></p>
  <p>Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web application</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24429 – Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24429</guid>
    <pubDate>Mon, 26 Jan 2026 18:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24429</strong></p>
  <p>Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial configuration. An attacker can leverage these default credentials to gain authenticated access to the management interface.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59102 – The web server of the Access Manager offers a functionality to download a backup...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59102</guid>
    <pubDate>Mon, 26 Jan 2026 10:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59102</strong></p>
  <p>The web server of the Access Manager offers a functionality to download a backup of the local database stored on the device. This database contains the whole configuration. This includes encrypted MIFARE keys, card data, user PINs and much more. The PINs are even stored unencrypted. Combined with the fact that an attacker can easily get access to the backup functionality by abusing the session ma…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59096 – The default password for the extended admin user mode in the application U9ExosA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59096</guid>
    <pubDate>Mon, 26 Jan 2026 10:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59096</strong></p>
  <p>The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is hard-coded in multiple locations as well as documented in the locally stored user documentation.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22273 – Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22273</guid>
    <pubDate>Fri, 23 Jan 2026 10:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22273</strong></p>
  <p>Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default Credentials vulnerability in the OS. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58744 – Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58744</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58744</strong></p>
  <p>Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in    Milner ImageDirector Capture on Windows allows decryption of document archive files using credentials decrypted with hard-coded application encryption key.  This issue affects ImageDirector Capture: from 7.0.9.0 before 7.6.3.25808.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-47796 – Denver SHC-150 Smart Wifi Camera contains a hardcoded telnet credential vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47796</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47796</guid>
    <pubDate>Fri, 16 Jan 2026 00:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-47796</strong></p>
  <p>Denver SHC-150 Smart Wifi Camera contains a hardcoded telnet credential vulnerability that allows unauthenticated attackers to access a Linux shell. Attackers can connect to port 23 using the default credential to execute arbitrary commands on the camera's operating system.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47796">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22910 – The device is deployed with weak and publicly known default passwords for certai...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22910</guid>
    <pubDate>Thu, 15 Jan 2026 13:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22910</strong></p>
  <p>The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1391</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25289 – SmartLiving SmartLAN &lt;=6.x contains an authenticated remote command injection vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25289</guid>
    <pubDate>Thu, 08 Jan 2026 00:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25289</strong></p>
  <p>SmartLiving SmartLAN <=6.x contains an authenticated remote command injection vulnerability in the web.cgi binary through the 'par' POST parameter with the 'testemail' module. Attackers can exploit the unsanitized parameter and system() function call to execute arbitrary system commands with root privileges using default credentials.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36915 – Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36915</guid>
    <pubDate>Tue, 06 Jan 2026 16:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36915</strong></p>
  <p>Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials to gain root-level access and execute system commands across multiple Adtec Digital product versions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36910 – Cayin Signage Media Player 3.0 contains an authenticated remote command injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36910</guid>
    <pubDate>Tue, 06 Jan 2026 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36910</strong></p>
  <p>Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-15111 – Ksenia Security lares (legacy model) version 1.6 contains a default credentials ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15111</guid>
    <pubDate>Tue, 30 Dec 2025 23:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-15111</strong></p>
  <p>Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploit the weak default administrative credentials to obtain full control of the home automation system.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-50803 – JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50803</guid>
    <pubDate>Tue, 30 Dec 2025 23:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-50803</strong></p>
  <p>JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the device with administrative privileges.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25147 – Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25147</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25147</guid>
    <pubDate>Wed, 24 Dec 2025 20:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25147</strong></p>
  <p>Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to the device by logging in with predefined username and password combinations.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25147">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-67418 – ClipBucket 5.5.2 is affected by an improper access control issue where the produ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67418</guid>
    <pubDate>Mon, 22 Dec 2025 20:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-67418</strong></p>
  <p>ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative credentials. An unauthenticated remote attacker can log in to the administrative panel using these default credentials, resulting in full administrative control of the application.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-56157 – Default credentials in Dify thru 1.5.1. PostgreSQL username and password specifi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-56157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-56157</guid>
    <pubDate>Thu, 18 Dec 2025 19:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-56157</strong></p>
  <p>Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67513 – FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67513</guid>
    <pubDate>Wed, 10 Dec 2025 23:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67513</strong></p>
  <p>FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone adm…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-13955 – Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13955</guid>
    <pubDate>Wed, 10 Dec 2025 09:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-13955</strong></p>
  <p>Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II before version 1.17478.177 allows attackers in Wi-Fi range to gain access to the dongle by calculating the default password from observable device identifiers</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54303 – The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default crede...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54303</guid>
    <pubDate>Thu, 04 Dec 2025 15:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54303</strong></p>
  <p>The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The ionadmin user account can be used to authenticate to default deployments with the password ionadmin. The user guide recommends changing default credentials; however, a password change policy for default administrative accounts is not enforced. Many deplo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-53963 – An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53963</guid>
    <pubDate>Thu, 04 Dec 2025 15:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-53963</strong></p>
  <p>An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The root account has a weak default password of ionadmin, and a password change policy for the root account is not enforced. Thus, an attacker with network connectivity can achieve root code execution. NOTE: This vulnerability only affects products that a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-63353 – A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63353</guid>
    <pubDate>Wed, 12 Nov 2025 16:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-63353</strong></p>
  <p>A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID. The device generates default passwords using a deterministic algorithm that derives the router passphrase from the SSID, enabling an attacker who can observe the SSID to predict the default password without authentication or user interac…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12218 – Weak Default Credentials.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12218</guid>
    <pubDate>Sat, 25 Oct 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12218</strong></p>
  <p>Weak Default Credentials.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41719 – A low privileged remote attacker can corrupt the webserver users storage on the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41719</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41719</guid>
    <pubDate>Wed, 22 Oct 2025 07:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41719</strong></p>
  <p>A low privileged remote attacker can corrupt the webserver users storage on the device by setting a sequence of unsupported characters which leads to deletion of all previously configured users and the creation of the default Administrator with a known default password.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1286</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41719">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-10678 – NetBird VPN when installed using vendor's provided script failed to remove or ch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10678</guid>
    <pubDate>Mon, 20 Oct 2025 16:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-10678</strong></p>
  <p>NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL. This issue affects instances installed using vendor's provided script. This issue may affect instances created with Docker if the default password was not changed nor the user was removed.  This issue has been fixed in version 0.57.0</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11943 – A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11943</guid>
    <pubDate>Sun, 19 Oct 2025 20:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11943</strong></p>
  <p>A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality of the component HTTP Web Server. The manipulation leads to use of default credentials. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34516 – Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34516</guid>
    <pubDate>Thu, 16 Oct 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34516</strong></p>
  <p>Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34223 – Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34223</guid>
    <pubDate>Mon, 29 Sep 2025 21:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34223</strong></p>
  <p>Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) contain a default admin account and an installation‑time endpoint at `/admin/query/update_database.php` that can be accessed without authentication. An attacker who can reach the installation web interface can POST arbitrary `root_user` and `root_…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-57428 – Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.Mini...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57428</guid>
    <pubDate>Mon, 29 Sep 2025 14:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-57428</strong></p>
  <p>Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port 23 and execute hardware-level flash and register manipulation commands.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10957 – This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10957</guid>
    <pubDate>Thu, 25 Sep 2025 12:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10957</strong></p>
  <p>This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. A remote attacker could exploit this vulnerability by establishing an FTP connection using default credentials, potentially gaining unauthorized access to configuration files, user credentials, or other sensitive information stored on the targeted device.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57295 – H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57295</guid>
    <pubDate>Thu, 18 Sep 2025 21:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57295</strong></p>
  <p>H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user account has no password set, and the H3C user account uses the default password "admin," both stored in the /etc/shadow file. Attackers with network access can exploit these credentials to gain unauthorized root-level access to the device via the administrativ…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-8077 – A vulnerability exists in NeuVector versions up to and including 5.4.5, where a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8077</guid>
    <pubDate>Wed, 17 Sep 2025 13:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-8077</strong></p>
  <p>A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default password for the built-in `admin` account. If this password is not changed immediately after deployment, any workload with network access within the cluster could use the default credentials to obtain an authentication token. This token can then be used to perform any operation via…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57579 – An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57579</guid>
    <pubDate>Fri, 12 Sep 2025 16:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57579</strong></p>
  <p>An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57578 – An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57578</guid>
    <pubDate>Fri, 12 Sep 2025 16:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57578</strong></p>
  <p>An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57577 – An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57577</guid>
    <pubDate>Fri, 12 Sep 2025 16:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57577</strong></p>
  <p>An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's position is that their "product lines enforce or clearly prompt users to change any initial credentials upon first use. At most, this would be a case of misconfiguration if an administrator deliberately ignored the prompts, which is outside the scope of CVE definit…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57577">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55051 – CWE-1392: Use of Default Credentials</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55051</guid>
    <pubDate>Tue, 09 Sep 2025 19:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55051</strong></p>
  <p>CWE-1392: Use of Default Credentials</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-9725 – A vulnerability was identified in Cudy LT500E up to 2.3.12. Affected is an unkno...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9725</guid>
    <pubDate>Sun, 31 Aug 2025 10:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-9725</strong></p>
  <p>A vulnerability was identified in Cudy LT500E up to 2.3.12. Affected is an unknown function of the file /squashfs-root/etc/shadow of the component Web Interface. The manipulation leads to use of hard-coded password. The attack must be carried out locally. The attack's complexity is rated as high. The exploitability is told to be difficult. The exploit is publicly available and might be used. Upgr…</p>
  <p><strong>CVSS:</strong> 2.5 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-10062 – A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-10062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-10062</guid>
    <pubDate>Sat, 30 Aug 2025 14:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-10062</strong></p>
  <p>A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload and execute arbitrary PHP code. The WebDAV service, accessible via /webdav/, accepts HTTP PUT requests using default credentials. This permits attackers to upload a malicious PHP payload and trigger its execution via a subsequent GET request, resultin…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-10062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-9589 – A vulnerability was determined in Cudy WR1200EA 2.3.7-20250113-121810. Affected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9589</guid>
    <pubDate>Thu, 28 Aug 2025 22:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-9589</strong></p>
  <p>A vulnerability was determined in Cudy WR1200EA 2.3.7-20250113-121810. Affected is an unknown function of the file /etc/shadow. Executing manipulation can lead to use of default password. The attack needs to be launched locally. A high complexity level is associated with this attack. The exploitability is told to be difficult. The exploit has been publicly disclosed and may be utilized. The vendo…</p>
  <p><strong>CVSS:</strong> 2.5 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-9577 – A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9577</guid>
    <pubDate>Thu, 28 Aug 2025 19:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-9577</strong></p>
  <p>A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the component Administrative Interface. The manipulation results in use of default credentials. Attacking locally is a requirement. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been released to…</p>
  <p><strong>CVSS:</strong> 2.5 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9577">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-9576 – A vulnerability was identified in seeedstudio ReSpeaker LinkIt7688. Impacted is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9576</guid>
    <pubDate>Thu, 28 Aug 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-9576</strong></p>
  <p>A vulnerability was identified in seeedstudio ReSpeaker LinkIt7688. Impacted is an unknown function of the file /etc/shadow of the component Administrative Interface. The manipulation leads to use of default credentials. An attack has to be approached locally. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit is publicly available and mi…</p>
  <p><strong>CVSS:</strong> 2.5 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-35114 – Agiloft Release 28 contains several accounts with default credentials that could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-35114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-35114</guid>
    <pubDate>Tue, 26 Aug 2025 23:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-35114</strong></p>
  <p>Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The password hash is known for at least one of the accounts and the credentials could be cracked offline. Users should upgrade to Agiloft Release 30.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-35114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-29525 – DASAN GPON ONU H660WM OS version H660WMR210825 Hardware version DS-E5-583-A1 was...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29525</guid>
    <pubDate>Mon, 25 Aug 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-29525</strong></p>
  <p>DASAN GPON ONU H660WM OS version H660WMR210825 Hardware version DS-E5-583-A1 was discovered to contain insecure default credentials in the modem's control panel.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-29521 – Insecure default credentials for the Adminsitrator account of D-Link DSL-7740C w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29521</guid>
    <pubDate>Mon, 25 Aug 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-29521</strong></p>
  <p>Insecure default credentials for the Adminsitrator account of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to escalate privileges via a bruteforce attack.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-57789 – During the brief window between installation and the first administrator login, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57789</guid>
    <pubDate>Wed, 20 Aug 2025 04:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-57789</strong></p>
  <p>During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-257</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57789">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-55740 – nginx-defender is a high-performance, enterprise-grade Web Application Firewall ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55740</guid>
    <pubDate>Tue, 19 Aug 2025 20:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-55740</strong></p>
  <p>nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engineered for modern web infrastructure. This is a configuration vulnerability affecting nginx-defender deployments. Example configuration files config.yaml and docker-compose.yml contain default credentials (default_password: "change_me_please", GF_SECURITY_ADMIN_PASSWORD=admin123).…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7342 – A security issue was discovered in the Kubernetes Image Builder where default cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7342</guid>
    <pubDate>Sun, 17 Aug 2025 23:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7342</strong></p>
  <p>A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the Windows image build process when using the Nutanix or VMware OVA providers. These credentials, which allow root access, are disabled at the conclusion of the build. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project and the vulnerab…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-10056 – PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-10056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-10056</guid>
    <pubDate>Wed, 13 Aug 2025 21:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-10056</strong></p>
  <p>PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnerability in its document upload functionality. Authenticated users can upload files to the mods/documents/uploads/ directory without any restriction on file type or extension. Because this directory is publicly accessible and lacks execution controls, attackers can upload a malicious PHP payload and execute it remotely.…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-10056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2184 – A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2184</guid>
    <pubDate>Wed, 13 Aug 2025 17:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2184</strong></p>
  <p>A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations.  The attacker must have network access to the Broker VM to exploit this issue.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-10042 – Sflog! CMS 1.0 contains an authenticated arbitrary file upload vulnerability in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-10042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-10042</guid>
    <pubDate>Fri, 08 Aug 2025 19:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-10042</strong></p>
  <p>Sflog! CMS 1.0 contains an authenticated arbitrary file upload vulnerability in the blog management interface. The application ships with default credentials (admin:secret) and allows authenticated users to upload files via manage.php. The upload mechanism fails to validate file types, enabling attackers to upload a PHP backdoor into a web-accessible directory (blogs/download/uploads/). Once uplo…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-10042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-8731 – A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8731</guid>
    <pubDate>Fri, 08 Aug 2025 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-8731</strong></p>
  <p>A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown part of the component SSH Service. The manipulation leads to use of default credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7769 – Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7769</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7769</guid>
    <pubDate>Wed, 06 Aug 2025 21:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7769</strong></p>
  <p>Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due to improper handling of user input. When used with default credentials, this enables attackers to execute arbitrary commands on the device that could cause potential unauthorized access, service disruption, and data exp…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7769">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-8530 – A vulnerability, which was classified as problematic, has been found in elunez e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8530</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8530</guid>
    <pubDate>Mon, 04 Aug 2025 23:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-8530</strong></p>
  <p>A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of the file eladmin-system\src\main\resources\config\application-prod.yml of the component Druid. The manipulation of the argument login-username/login-password leads to use of default credentials. The attack may be launched remotely. The exploit h…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8530">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-10059 – An authenticated OS command injection vulnerability exists in various D-Link rou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-10059</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-10059</guid>
    <pubDate>Fri, 01 Aug 2025 21:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-10059</strong></p>
  <p>An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmware version 8.04) via the tools_vct.htm endpoint. The web interface fails to sanitize input passed from the ping_ipaddr parameter to the tools_vct.htm diagnostic interface, allowing attackers to inject arbitrary shell commands using backtick encapsulation. With default credential…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-10059">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30125 – An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30125</guid>
    <pubDate>Mon, 28 Jul 2025 15:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30125</strong></p>
  <p>An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which creates an insecure-by-default condition. For users who change their passwords, it's limited to 8 characters. These short passwords can be cracked in 8 hours via low-end commercial cloud resources.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30133 – An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30133</guid>
    <pubDate>Mon, 28 Jul 2025 14:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30133</strong></p>
  <p>An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IROAD X View" app for authentication, but its HTTP server lacks this restriction. Once connected to the dashcam's Wi-Fi network via the default password ("qwertyuiop"), an attacker can directly access the HTTP server at http://192.168.10.1 without undergo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-29629 – Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29629</guid>
    <pubDate>Fri, 25 Jul 2025 17:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-29629</strong></p>
  <p>Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-43021 – A potential security vulnerability has been identified in the Poly Clariti Manag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43021</guid>
    <pubDate>Tue, 22 Jul 2025 23:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-43021</strong></p>
  <p>A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the use and retrieval of the default password. HP has addressed the issue in the latest software update.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54137 – HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS bac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54137</guid>
    <pubDate>Tue, 22 Jul 2025 22:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54137</strong></p>
  <p>HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend. Versions 11.0.9 and below were distributed with hardcoded default credentials for the user and superuser accounts. Additionally, the application has default private keys for JWTs. Users aren't prompted to change credentials or secrets during installation, and there is no way to change them through the UI. An una…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-7907 – A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been classi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7907</guid>
    <pubDate>Sun, 20 Jul 2025 21:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-7907</strong></p>
  <p>A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been classified as problematic. Affected is an unknown function of the file ruoyi-admin/src/main/resources/application-druid.yml of the component Druid. The manipulation leads to use of default credentials. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53758 – This vulnerability exists in Digisol DG-GR6821AC Router due to use of default ad...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53758</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53758</guid>
    <pubDate>Wed, 16 Jul 2025 12:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53758</strong></p>
  <p>This vulnerability exists in Digisol DG-GR6821AC Router due to use of default admin credentials at its web management interface. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the hardcoded default credentials stored in the firmware of the targeted device.  Successful exploitation of this vulnerability co…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53758">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-7503 – An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7503</guid>
    <pubDate>Fri, 11 Jul 2025 19:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-7503</strong></p>
  <p>An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet service (port 23) with undocumented, default credentials. The Telnet service is enabled by default and is not disclosed or configurable via the device’s web interface or user manual. An attacker with network access can authenticate using default credentials and gain root-level shell access to the devi…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34058 – Hikvision Streaming Media Management Server v2.3.5 uses default credentials that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34058</guid>
    <pubDate>Tue, 01 Jul 2025 15:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34058</strong></p>
  <p>Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary file read vulnerability in the /systemLog/downFile.php endpoint via directory traversal in the fileName parameter. This exploit chain can enable unauthorized ac…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-6951 – A vulnerability classified as problematic was found in SAFECAM X300 up to 202506...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6951</guid>
    <pubDate>Tue, 01 Jul 2025 12:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-6951</strong></p>
  <p>A vulnerability classified as problematic was found in SAFECAM X300 up to 20250611. This vulnerability affects unknown code of the component FTP Service. The manipulation leads to use of default credentials. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6529 – A vulnerability was found in 70mai M300 up to 20250611 and classified as critica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6529</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6529</guid>
    <pubDate>Mon, 23 Jun 2025 23:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6529</strong></p>
  <p>A vulnerability was found in 70mai M300 up to 20250611 and classified as critical. Affected by this issue is some unknown functionality of the component Telnet Service. The manipulation leads to use of default credentials. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure bu…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6529">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-24288 – The Versa Director software exposes a number of services by default and allow at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24288</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24288</guid>
    <pubDate>Thu, 19 Jun 2025 00:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-24288</strong></p>
  <p>The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes ssh and postgres to the internet, alongside a host of other services.  Versa Networks is not aware of any reported instance where this vulner…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24288">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5484 – A username and password are required to authenticate to the central 
SinoTrack d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5484</guid>
    <pubDate>Thu, 12 Jun 2025 20:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5484</strong></p>
  <p>A username and password are required to authenticate to the central  SinoTrack device management interface. The username for all devices is  an identifier printed on the receiver. The default password is  well-known and common to all devices. Modification of the default  password is not enforced during device setup. A malicious actor can  retrieve device identifiers with either physical access or…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-1390</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-40585 – A vulnerability has been identified in Energy Services (All versions with G5DFR)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40585</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40585</guid>
    <pubDate>Tue, 10 Jun 2025 16:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-40585</strong></p>
  <p>A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain default credentials. This could allow an attacker to gain control of G5DFR component and tamper with outputs from the device.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40585">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46612 – The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46612</guid>
    <pubDate>Tue, 10 Jun 2025 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46612</strong></p>
  <p>The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary commands via a wizard/workspace.jsp unrestricted file upload. To exploit this, the attacker must login to the administrator console (default credentials are weak and easily guessable) and upload a JSP file via the Panel Designer dashboard.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2766 – 70mai A510 Use of Default Password Authentication Bypass Vulnerability. This vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2766</guid>
    <pubDate>Fri, 06 Jun 2025 19:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2766</strong></p>
  <p>70mai A510 Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of 70mai A510. Authentication is not required to exploit this vulnerability.  The specific flaw exists within the default configuration of user accounts. The configuration contains default password. An attacker can leverage…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2766">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
