Skip to main content

About CWE-1188

MITRE rates the impact as varying by context, because the damage depends on what the insecure default controls. Its observed examples include a database browser whose default mode exposes a web server to the network and a firmware variable default that allows denial of service.

MITRE name
Initialization of a Resource with an Insecure Default
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Incomplete

Mitigations

  • +Ship a secure configuration as the default baseline, so the product resists common attacks without extra setup.
  • +Do not ship universally shared default passwords; require a strong password during installation or set a unique password per device.
  • +Make multifactor authentication for privileged users opt-out rather than opt-in.
  • +Move hardening guide settings into the default configuration and document risky changes in a loosening guide instead.
  • +Use threat modeling to decide which features and protocols are enabled by default.

Detection
MITRE lists automated static analysis (SAST), which can find some instances by tracing data flow from input sources to sinks.

CWE-1188 Vulnerabilities

5 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2025-48927
TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability
TeleMessage5.311.1%KEV2025-05-28
CVE-2023-27524
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
Apache Software Foundation8.997.4%KEV2023-04-24
CVE-2023-6448
Unitronics VisiLogic uses a default administrative password
Unitronics9.82.1%KEV2023-12-05
CVE-2022-24706
Remote Code Execution Vulnerability in Packaging
Apache Software Foundation9.892.5%KEV2022-04-26
CVE-2026-66066
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
rails9.527.9%2026-07-30

Most Affected Vendors

Frequently Asked Questions

What is CWE-1188?→

CWE-1188 is the initialization of a resource with an insecure default: a setting the product expects an administrator to change ships in a state that is not secure. MITRE renamed it from Insecure Default Initialization of Resource in October 2023.

Is a default password an example of CWE-1188?→

A universally shared default password is an insecure default of this kind. CISA and partner agencies advise manufacturers to eliminate default passwords by requiring a strong password at setup or shipping a unique password for each device.

How many exploited vulnerabilities are classified as CWE-1188?→

This database lists 5 CVE records mapped to CWE-1188 by their CVE Numbering Authority. 4 of them are in the CISA Known Exploited Vulnerabilities catalog. Examples include CVE-2025-48927, CVE-2023-27524, CVE-2023-6448.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.