Threadlinqs IntelligenceStart free

Weakness · BaseCWE-1392

CWE-1392: Use of Default Credentials

Base

As of 2026-10-10, CWE-1392 (Use of Default Credentials) underlies 3 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 19 tracked threats.

CVEs
3Mapped to CWE-1392
CISA KEV
0None listed yet
Critical
1CVSS v3 critical CVEs
Threats
19Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-1392?

The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

It is common practice for products to be designed to use default keys, passwords, or other mechanisms for authentication. The rationale is to simplify the manufacturing process or the system administrator's task of installation and deployment into an enterprise. However, if admins do not change the defaults, it is easier for attackers to bypass authentication quickly across multiple organizations.

CWE-1392 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific; Operating_System: Not OS-Specific; Architecture: Not Architecture-Specific; Technology: ICS/OT; Technology: Not Technology-Specific.

Source: MITRE CWE (CWE-1392 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Authentication — Gain Privileges or Assume Identity

Source: MITRE CWE, common consequences.

How CWE-1392 is exploited in the wild

Threadlinqs maps 3 CVEs to CWE-1392, published between 2024-12-27 and 2026-07-14. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 1 critical, 2 high. The highest EPSS score in the set is 84.1% (CVE-2024-12856), the modelled probability of exploitation in the next 30 days. 19 tracked threats reference CWE-1392 directly or through a CVE it covers; the most recent is “FortiBleed: Credential-Harvesting Campaign Compromising 86,644+ Fortinet FortiGate Devices and Locking Out Admins (FBI/USSS JCSA-20261006-01)” (2026-10-07). Affected products concentrate in Dell (1), Four-Faith (1), SAP_SE (1).

Vulnerabilities (CVEs)

All 3 CVEs mapped to CWE-1392, CISA KEV first, then by CVSS score.

Affected vendors

  • Dell — 1 CVE
  • Four-Faith — 1 CVE
  • SAP_SE — 1 CVE

Threat activity

19 tracked threats cite CWE-1392:

Mitigations

  • Requirements: Prohibit use of default, hard-coded, or other values that do not vary for each installation of the product - especially for separate organizations.
  • Architecture and Design: Force the administrator to change the credential upon installation.
  • Installation, Operation: The product administrator could change the defaults upon installation or during operation.

Source: MITRE CWE, potential mitigations.