References https://www.ddosi.org/afrog/ https://cve.imfht.com/poc_detail/26f91b6525442770a3b8ca2ec49610c52b2ab245 https://cn-sec.com/archives/1325701.html https://mygit.osfipin.com/release/51966753 https://gitextract.com/qi4L/qscan https://router-network.com/telecom-router-login https://wiki.matrixcomsec.com/index.php?title=How_to_Default_IP_Address_And_Password_Of_Telecom_Products%3F
Related VulnerabilitiesPoCCVE-2023-54391: Proxmox VE - Default Credentials with TFA BypassPoCCVE-2026-62382: PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership BypassPoCjohnson-controls-default-login: Johnson Controls Frick Quantum HD Compressors - Default Login仁和兴业(深圳)软件有限公司仁和云ERP userresetPassword.action 存在任意账号密码重置漏洞PoClitellm-default-login: LiteLLM - Default LoginPoCCVE-2026-45332: Automad < 2.0.0-beta.28 - Unauthenticated Admin Password Hash DisclosurePoCnet-vision-default-login: Net Vision UPS Monitor - Default LoginPoC3xui-default-login: 3X-UI - Default LoginMicrosoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)metaBase reset_password 接口存在sql注入漏洞PoCCVE-2026-44825: Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default CredentialsPoCCVE-2026-52824: Kimai <= 2.57.0 - Default APP_SECRET Authentication BypassPoCsentinel-default-login: Alibaba Sentinel - Default Login