OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docke
eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that a
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remot
OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product
Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and wri
Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the c
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticate
JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that
AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers t
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final manag
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships def
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from samp
netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0
Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default C
BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default passwo
IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis uses default passwords default pass
The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password c
A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized ac
A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-c
Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Credentials" vulnerability. A low privileged att
Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera
Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauth
Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in Milner ImageDirector Cap
Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of I
Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyb
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high
A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Perform
IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default pas
By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the p
Default credentials vulnerability exists in SuprOS product. If exploited, this could allow an authenticated local attack
Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have cre
Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface mo
Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain
Frequently Asked Questions
What is CWE-1392?
CWE-1392 (CWE-1392) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1392?
There are 35 CVE records associated with CWE-1392 in our database. Of these, 14 are critical severity, 13 are high severity, and 3 are medium severity.
How can I protect against CWE-1392 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1392 using AI-powered security agents.
Detect CWE-1392 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1392 vulnerabilities across your infrastructure.
Get Started