What is CWE-1392?
The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.
It is common practice for products to be designed to use default keys, passwords, or other mechanisms for authentication. The rationale is to simplify the manufacturing process or the system administrator's task of installation and deployment into an enterprise. However, if admins do not change the defaults, it is easier for attackers to bypass authentication quickly across multiple organizations.
CWE-1392 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Operating_System: Not OS-Specific; Architecture: Not Architecture-Specific; Technology: ICS/OT; Technology: Not Technology-Specific.
Source: MITRE CWE (CWE-1392 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Authentication — Gain Privileges or Assume Identity
Source: MITRE CWE, common consequences.
How CWE-1392 is exploited in the wild
Threadlinqs maps 3 CVEs to CWE-1392, published between 2024-12-27 and 2026-07-14. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 1 critical, 2 high. The highest EPSS score in the set is 84.1% (CVE-2024-12856), the modelled probability of exploitation in the next 30 days. 19 tracked threats reference CWE-1392 directly or through a CVE it covers; the most recent is “FortiBleed: Credential-Harvesting Campaign Compromising 86,644+ Fortinet FortiGate Devices and Locking Out Admins (FBI/USSS JCSA-20261006-01)” (2026-10-07). Affected products concentrate in Dell (1), Four-Faith (1), SAP_SE (1).
Vulnerabilities (CVEs)
All 3 CVEs mapped to CWE-1392, CISA KEV first, then by CVSS score.
- CVE-2026-44761 — CVSS 9.1 critical · published 2026-07-14
- CVE-2026-32652 — CVSS 7.8 high · published 2026-06-17
- CVE-2024-12856 — CVSS 7.2 high · EPSS 84.1% · published 2024-12-27
Affected vendors
Threat activity
19 tracked threats cite CWE-1392:
- FortiBleed: Credential-Harvesting Campaign Compromising 86,644+ Fortinet FortiGate Devices and Locking Out Admins (FBI/USSS JCSA-20261006-01)CRITICAL
- Exposed Industrial Controllers (Rockwell MicroLogix 1100/1400, Unitronics) Hijacked in July 2026 Campaign Against US Water UtilitiesHIGH
- "Ancient" Linux IoT botnet with custom ANCT C2 protocol (Telnet-spreading, DNS-over-TLS C2 resolution)MEDIUM
- SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (CVE-2026-58231, CVSS 10.0)CRITICAL
- Botnet Scanning Internet-Exposed Router Diagnostic Tools Exploiting OS Command Injection (CVE-2024-12856, CVE-2013-7179, CVE-2020-8949, CVE-2024-48419)HIGH
- CVE-2026-44747: Critical Memory Corruption in SAP NetWeaver Application Server ABAP (CVSS 9.9)CRITICAL
- SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761)CRITICAL
- SAP July 2026 Patch Day: Critical Memory Corruption in NetWeaver ABAP (CVE-2026-44747, CVSS 9.9) Among 16 Security NotesCRITICAL
- SAP Patches CVSS 9.9 NetWeaver ABAP Out-of-Bounds Write Flaw (CVE-2026-44747), Plus Critical Approuter and Commerce Cloud BugsCRITICAL
- LastPass Customer CRM Data Exposed via Klue OAuth Token Theft (Icarus Salesforce Supply-Chain Campaign)MEDIUM
- FortiBleed: Russian-Speaking Initial Access Broker Weaponizes FortiOS 'diagnose sniffer packet' (FortigateSniffer) to Harvest 110M+ Credentials From ~430,000 FortiGate FirewallsCRITICAL
- World Leaks Ransomware Group Breaches Tata Electronics — 630GB / 200,000+ Files Including Apple 'com.apple.factorydata' and Tesla Project Highland Design DataHIGH
- FortiBleed: Russian Initial-Access-Broker Credential-Harvesting Campaign Weaponizing FortiGate Firewalls with the FortigateSniffer ToolHIGH
- FortiBleed Campaign: Custom FortigateSniffer Abuses FortiOS 'diagnose sniffer packet' to Harvest Credentials Across 24 ProtocolsCRITICAL
- FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and SSL VPN GatewaysCRITICAL
- FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN Firewalls Across 194 CountriesHIGH
- P2P Botnets in the Wild: Pink, Hajime, Mozi, FritzFrog, and Panchan — Decentralized C2 Landscape (360 Netlab Continuous Monitoring)HIGH
- Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS — 47.1M Attacks in 2025, Night Before Christmas Campaign, 1-4M Infected Android TVs, Operator 'Forky' IdentifiedCRITICAL
- Default ICS Credentials Exploited in Destructive Attack on Polish Energy FacilitiesCRITICAL
Mitigations
- Requirements: Prohibit use of default, hard-coded, or other values that do not vary for each installation of the product - especially for separate organizations.
- Architecture and Design: Force the administrator to change the credential upon installation.
- Installation, Operation: The product administrator could change the defaults upon installation or during operation.
Source: MITRE CWE, potential mitigations.