Vulnerabilities (CVE)

Filtered by CWE-1392
Total 6 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-4622 2024-05-15 N/A N/A
If misconfigured, alpitronic Hypercharger EV charging devices can expose a web interface protected by authentication. If the default credentials are not changed, an attacker can use public knowledge to access the device as an administrator.
CVE-2024-31069 2024-04-15 N/A 7.4 HIGH
IO-1020 Micro ELD web server uses a default password for authentication.
CVE-2024-30210 2024-04-15 N/A 7.4 HIGH
IO-1020 Micro ELD uses a default WIFI password that could allow an adjacent attacker to connect to the device.
CVE-2024-29844 2024-04-15 N/A 9.8 CRITICAL
Default credentials on the Web Interface of Evolution Controller 2.x (123 and 123) allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the password. There is no warning or prompt to ask the user to change the default password.
CVE-2023-49621 1 Siemens 1 Simatic Cn 4100 2024-01-11 N/A 9.8 CRITICAL
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application uses default credential with admin privileges. An attacker could use the credentials to gain complete control of the affected device.
CVE-2023-3703 1 Proscend 40 A510-f1, A510-f1 Firmware, A510-l1 and 37 more 2023-12-10 N/A 9.8 CRITICAL
Proscend Advice ICR Series routers FW version 1.76 - CWE-1392: Use of Default Credentials