King of Spoofing I
Your system ships with a default admin password and doesn’t force a change.
Threat |
|
When you buy a router, it has the admin password on the back. Some vendors use the same one for everyone and detail it in the user manual. |
|
CAPEC |
CAPEC-70 - Try Common or Default Usernames and Passwords |
ASVS |
2.5.4 - Ensure shared or default accounts have been removed 2.3.1 - Ensure forced change of password on first login |
CWE |
CWE-1392 - Use of Default Credentials CWE-1393 - Use of Default Password |
Mitigations |
|
|