Threats Tagged 'cwe-1391'
View all threats tagged with 'cwe-1391'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-1391'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-47325: CWE-1391 Use of Weak Credentials in ProjectsAndPrograms school-management-systemCVE-2026-47325 0 ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's passwords solely from the user’s date of birth (e.g., 12072000 for 12 July 2000). The application does not require or prompt users to change the password upon first login. This behavior allows attackers to easily guess or derive valid credentials, leading to unauthorized account access. The maintainers were notified early about this vulnerability but did not provide details regarding affected versions. The version corresponding to commit 6b6fae5 was tested and confirmed vulnerable; other versions were not tested and may also be affected. Join the discussion | CVE Database V5 | 06/03/2026, 13:28:25 UTC Added: 06/03/2026, 14:18:47 UTC |
CVE-2026-4377: CWE-1391 Use of Weak Credentials in D-Link Corporation DWR-X1820CVE-2026-4377 0 Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. An attacker who knows how passwords are generated can easily crack the default password if they have the device IMEI number. This issue was fixed in version 1.00B16CP. Join the discussion | CVE Database V5 | 05/28/2026, 09:02:44 UTC Added: 05/28/2026, 10:18:45 UTC |
CVE-2026-35089: CWE-1391 Use of Weak Credentials in Slican IPxCVE-2026-35089 0 In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can be obtained without authentication. An unauthenticated attacker can deduce the secure key and obtain admin credentials. This issue was fixed in versions below: - IPx series: version 6.61.0040 - CCT-1668: version 6.56.0430 - MAC-6400: version 6.56.0430 - CXS-0424: version 6.30.0510 The issue STILL EXISTS in End-Of-Life telephone exchanges in versions 4.xx and below: - CCT-1668 (CCT1CPU) - MAC-6400 - CXS-0424 These products were discontinued in 2011 and 2012 and and will not receive updates. These products require a hardware update in order to receive a software update. The vendor recommends that users of these devices contact the their service department directly to determine the options for upgrading. Join the discussion | CVE Database V5 | 05/27/2026, 12:42:19 UTC Added: 05/27/2026, 14:03:57 UTC |
Showing 1 to 3 of 3 results