By weakness (CWE)
CWE-1392: related vulnerabilities
CVEs classified under CWE-1392. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
5 published vulnerabilities
- CVE-2026-42941HIGH 8.3
Danelec MacGregor's Voyage Data Recorder (VDR) devices ship with hardcoded default credentials that cannot be forced to change, allowing unauthenticated network attackers to gain administrative access. This is a straightforward but high-impact authentication bypass on a maritime safety-critical system.
- CVE-2026-3144HIGH 8.1
IBM API Connect versions 12.1.0.0 through 12.1.0.3 ship with hardcoded default credentials that remain active until administrators manually enforce a password change. An attacker with network access can use these credentials to gain full unauthorized access to the API management platform before credential enforcement takes effect, potentially compromising API infrastructure, traffic, and data.
- CVE-2026-32652HIGH 7.8
Dell AIOps Collector versions before 1.18.3 ship with hardcoded or default credentials that a local attacker can exploit to gain broad filesystem access. The vulnerability only affects new installations; systems that have been patched or upgraded to 1.18.3 or later are protected, regardless of their original version. This is a local-only attack requiring console access—remote exploitation is not possible.
- CVE-2026-50005HIGH 7.7
Brickcom IP cameras are shipped with hardcoded default credentials that cannot be easily changed, allowing anyone with network access to view live camera feeds without authentication. An attacker does not need to exploit a software flaw—they simply use the well-known default username and password to log in remotely. This is a configuration and design issue, not a traditional code vulnerability, but the impact is severe: loss of surveillance confidentiality and potential reconnaissance for physical security breaches.
- CVE-2026-44273MEDIUM 6.0
Dell Wyse Management Suite before version 2605 contains a default credentials vulnerability that allows a high-privileged local user to access sensitive information. An attacker already holding elevated administrative privileges on the system could use hardcoded or default credentials to bypass authentication controls and obtain confidential data stored within the management suite. This is not a network-accessible vulnerability and requires both local system access and high-level privileges to exploit.