CVE-2025-1392
published 2025-02-17CVE-2025-1392: A vulnerability has been found in D-Link DIR-816 1.01TO and classified as problematic. Affected by this vulnerability is an unknown functionality of the file…
PriorityP336medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
6.82%
93.3th percentile
A vulnerability has been found in D-Link DIR-816 1.01TO and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/webproc?getpage=html/index.html&var:menu=24gwlan&var:page=24G_basic. The manipulation of the argument SSID leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dir-816 | — | — |
| dlink | dir-816_firmware | — | — |
| github.com | anipaleja_nginx-defender | >= 0 < 1.5.0 | 1.5.0 |
| github.com | filebrowser_filebrowser | 0 – 1.11.0 | — |
| github.com | filebrowser_filebrowser_v2 | >= 0 < 2.34.1 | 2.34.1 |
| github.com | netbirdio_netbird | >= 0 < 0.57.0 | 0.57.0 |
| haxtheweb | haxcms-nodejs | >= 0 < 11.0.10 | 11.0.10 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv4.05.1MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
NetBird VPN does not remove the default password of an admin account
ghsa·2025-10-20
CVE-2025-10678 [CRITICAL] CWE-1392 NetBird VPN does not remove the default password of an admin account
NetBird VPN does not remove the default password of an admin account
NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL.
This issue affects instances installed using vendor's provided script. This issue may affect instances created with Docker if the default password was not changed nor the user was removed.
This issue has been fixed in version 0.57.0.
GHSA
Default Credentials in nginx-defender Configuration Files
ghsa·2025-08-19
CVE-2025-55740 [MEDIUM] CWE-1392 Default Credentials in nginx-defender Configuration Files
Default Credentials in nginx-defender Configuration Files
### Impact
This is a configuration vulnerability affecting nginx-defender deployments. Example configuration files
[config.yaml](https://github.com/Anipaleja/nginx-defender/blob/main/config.yaml), [docker-compose.yml](https://github.com/Anipaleja/nginx-defender/blob/main/docker-compose.yml) contain default credentials (`default_password: "change_me_please"`, `GF_SECURITY_ADMIN_PASSWORD=admin123`). If users deploy nginx-defender without changing these defaults, attackers with network access could gain administrative control, bypassing security protections.
**Who is impacted?**
All users who deploy nginx-defender with default credentials and expose the admin interface to untrusted networks.
### Patches
The issue is addressed in v1.
GHSA
NodeJS version of the HAX CMS application is distributed with Default Secrets
ghsa·2025-07-21
CVE-2025-54137 [HIGH] CWE-1392 NodeJS version of the HAX CMS application is distributed with Default Secrets
NodeJS version of the HAX CMS application is distributed with Default Secrets
### Summary
The NodeJS version of the HAX CMS application is distributed with hardcoded default credentials for the user and superuser accounts. Additionally, the application has default private keys for JWTs. Users aren't prompted to change credentials or secrets during installation, and there is no way to change them through the UI.
### Affected Resources
- [HAXCMS.js](https://github.com/haxtheweb/haxcms-nodejs/blob/main/src/lib/HAXCMS.js#L1614) HAXCMSClass
### Impact
An unauthenticated attacker can read the default user credentials and JWT private keys from the public haxtheweb GitHub repositories. These credentials and keys can be used to access unconfigured self-hosted instances of the application, mod
GHSA
File Browser vulnerable to insecure password handling
ghsa·2025-06-30
CVE-2025-52997 [MEDIUM] CWE-1392 File Browser vulnerable to insecure password handling
File Browser vulnerable to insecure password handling
## Summary ##
All user accounts authenticate towards a *File Browser* instance with a password. A missing password policy and brute-force protection makes it impossible for administrators to properly secure the authentication process.
## Impact ##
Attackers can mount a brute-force attack against the passwords of all accounts of an instance. Since the application is lacking the ability to prevent users from choosing a weak password, the attack is likely to succeed.
## Vulnerability Description ##
The application implement a classical authentication scheme using a username and password combination. While employed by many systems, this scheme is quite error-prone and a common cause for vulnerabilities. File Browser's implementation h
GHSA
GHSA-8pp4-8qq6-hjcg: A vulnerability has been found in D-Link DIR-816 1
ghsa_unreviewed·2025-02-17
CVE-2025-1392 [MEDIUM] CWE-79 GHSA-8pp4-8qq6-hjcg: A vulnerability has been found in D-Link DIR-816 1
A vulnerability has been found in D-Link DIR-816 1.01TO and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/webproc?getpage=html/index.html&var:menu=24gwlan&var:page=24G_basic. The manipulation of the argument SSID leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Ivanti
Ivanti Security Advisory: CVE-2025-22460
vendor_ivanti·2025-05-13·CVSS 7.8
CVE-2025-22460 [HIGH] CWE-1392 Ivanti Security Advisory: CVE-2025-22460
Ivanti Security Advisory: CVE-2025-22460
Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.
CVE IDs: CVE-2025-22460
CVSS Base Score: 7.8
Severity: HIGH
CWEs: CWE-1392
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-17
Published