Why standard passwords can give attackers direct access to your systems

Jonas Buchholz
by Jonas Buchholz · 27.09.2026

01 Technical background

A single weak password can be enough for an attacker to take control of a system. In practice, weak passwords arise in particular in two situations:

On the one hand, it may happen that Factory-preset access data after commissioning not changed Many systems, such as routers, network cameras, databases, and web application administration interfaces, are delivered with a preconfigured user account and a default password, for example „admin/admin“ or „root/12345“. These are intended solely for initial configuration and should be replaced immediately thereafter with individual access credentials.

On the other hand, users sometimes choose passwords that are easy to guess or are already known from previous data leaks. These passwords can be used by attackers automatically for login attempts using publicly available password lists. Examples include simple sequences of numbers such as „123456“, easily predictable passwords such as „passwort1“, or passwords that have already been compromised in previous data leaks. The most famous collections include the „Pwned Passwords“ from Have I Been Pwned, which contain compromised passwords from numerous published data leaks.

Both scenarios ultimately lead to the same result: An attacker does not need to crack the password; they already know it or can derive it from a manageable number of possible passwords. Although the causes are different, in both cases avoidable vulnerabilities in authentication arise, which can be prevented through appropriate organizational and technical measures.

Standard password and Weak password

02 Risks and impacts

Unchanged standard access methods and insufficient password requirements are among the most significant vulnerabilities in authentication. This is also reflected in the OWASP Top 10, an internationally recognized overview of the most significant security risks for web applications: Both vulnerabilities are assigned to the category A07:2021 „Identification and Authentication Failures“. Although the causes are different, they ultimately lead to the same critical security problem: unauthorized access to systems and data.

To exploit these vulnerabilities, attackers use, among other things, automated methods. While in Credential Stuffing, access data from previous data leaks is used, in Password Spraying frequently used passwords are tested against numerous user accounts. Whether such an attack is successful depends, among other things, on whether the system limits login attempts or employs additional protection measures, such as multi-factor authentication. Unchanged standard logins in particular pose a significant security risk here, as attackers can often research the factory-default access data without much effort from publicly available manufacturer documentation or other commonly available sources. Unchanged standard logins are particularly common in test systems, backup interfaces, and rarely used administrative access points.

If authentication is successful, the attacker gains access to the respective user account or the administration interface. Depending on their permissions, they can change configurations, view data, or use the system as a starting point for further attacks.

From a data protection perspective, Article 32 of the GDPR requires controllers to protect data processing systems against unauthorized access through appropriate technical and organizational measures. The standard for selecting these measures is the state of the art. Particular guidance can be found in, for example, Recommendations from the Federal Office for Information Security (BSI). This includes, among other things, the use of individual and sufficiently strong passwords, the exchange of standard passwords, and measures to detect compromised passwords. Additionally, the Guidelines of the US National Institute of Standards and Technology (NIST) These recommend at least 15 characters for exclusive password logins and at least 8 characters combined with a second authentication factor; the length of the password is weighted higher than rigid complexity requirements.

If the exploitation of such a vulnerability leads to the unauthorized disclosure, modification, or loss of personal data, a violation of personal data protection (data protection incident) is usually present.

03 How to identify the vulnerability

Detecting this vulnerability requires two steps, as unchanged standard access methods and insecure passwords have different causes and therefore require different checks and countermeasures. This distinction is also reflected in the Common Weakness Enumeration (CWE) , According to an internationally established list for classifying vulnerabilities, unchanged standard access methods are assigned to CWE-798 („Use of Hard-coded Credentials“), insufficient password requirements of CWE-521 („Weak Password Requirements“).

1st exam on standard access methods (CWE-798)

First, check each system for documented factory access using the manufacturer documentation. Then, verify that the access data still works. If this is the case, the default access data has not been replaced and the vulnerability exists.

2nd Pass Test for Password Quality (CWE-521)

For password quality, a single password can be tested against the PwnedPasswords database without disclosing the plaintext. This is done locally by generating a SHA-1 hash and only transmitting a portion of the hash value to the interface. This so-called k-anonymity method allows verification without having to transmit the actual password to the service:

bash echo -n „Your password“ | sha1sum

The first five characters of the hashwert can then be queried:

Bash curl https://api.pwnedpasswords.com/range/5BAA6

If the rest of your own hash value appears in the response list, the password has already been recorded in a data breach.

A vulnerability exists when standard access methods are still used or an active password is already known to be compromised.

04 How to fix the vulnerability

The remediation of the vulnerability depends on its cause. Unchanged standard access points must be permanently removed, while insecure or already compromised passwords must be replaced with secure alternatives.

Eliminating 1st standard access points (CWE-798)

  • First, create an overview of all systems, devices, and accounts with access data.
  • Change all factory-default passwords before the productive commissioning of a system, and do not deactivate or remove unnecessary standard accounts.
  • After firmware updates or resetting to factory settings, it should be checked whether default access has been re-enabled or passwords have been reset to factory settings.

2. Replacing insecure passwords (CWE-521)

  • Implement a state-of-the-art password policy that provides a sufficient minimum length and a comparison of new passwords against known breach lists.
  • Replace weak or already compromised passwords with individual, sufficiently long passwords that have not yet been compromised.

3. Additional protective measures

  • Enable multi-factor authentication where available.
  • Reduce the number of failed login attempts to make automated password attacks more difficult.
  • Record and monitor failed logins to identify and respond to attack attempts early on.

After implementation, conduct another audit. The vulnerability is only considered resolved when no standard access points are active and all affected accounts use individual, sufficiently strong and uncompromised passwords.

In practice, several vulnerabilities exist simultaneously in publicly accessible systems. Without systematic testing, standard passwords and other configuration errors often remain undetected.

FAQ

Why are standard passwords a security risk?


Which systems are particularly often affected?


Which attacks are favored by weak or known passwords?

What significance do standard passwords have in light of the GDPR?


How can it be determined whether there is a corresponding vulnerability?


How can standard passwords and insecure passwords be effectively eliminated?