Join GitHub today
GitHub is home to over 50 million developers working together to host and review code, manage projects, and build software together.
Sign upGitHub is where the world builds software
Millions of developers and companies build, ship, and maintain their software on GitHub — the largest and most advanced development platform in the world.
| #SCADA StrangeLove Default/Hardcoded Passwords List | |||||||
|---|---|---|---|---|---|---|---|
| #Find more at http://www.scada.sl | |||||||
| #Please contact us at scadastrangelove@gmail.com and @scadasl | |||||||
| #release 1.1 by Oxana Andreeva (oxana.andreeva@inbox.ru) | |||||||
| Vendor | Device | Default password | Port | Device type | Protocol | Source | |
| ABB | AC 800M | service:ABB800xA | Controller | https://library.e.abb.com/public/f355a67551218ae7c1257dc0003298c5/3BDS021515-600_-_en_AC_800M_6.0_PROFINET_IO_Configuration.pdf | |||
| ABB | SREA-01 | admin:admin | 80/tcp | Ethernet Adapter Module | http | https://www.inverterdrive.com/file/ABB-SREA-01-Manual | |
| Adcon Telemetry | Telemetry Gateway A840 and Wireless Modem A440 | root:840sw | terminal program | Base Station | http://www.adcon.com/index.php?option=com_docman&task=doc_download&gid=41&Itemid=239&lang=de | ||
| Adcon Telemetry | addVANTAGE Pro 6.1, 6.5 | root:root | 8080/tcp | HMI | HTTP | http://adcon.com/index.php?option=com_docman&task=doc_download&gid=31&Itemid=239&lang=en, http://scient.static.otenet.gr:8080/doc/admin_help_en.pdf | |
| Advantech | SNMP-1000, MIC-3924 | advantech:admin | serial port | system management module, intelligent chassis management module | http://support.elmark.com.pl/advantech/pdf/SNMP-1000man.pdf, https://ecauk.com/files/2011/08/Advantech-MIC-3924-User-Manual.pdf | ||
| Advantech | Advantech WebAccess browser-based HMI and SCADA software | admin:blank | 80/tcp | browser-based HMI and SCADA software | HTTP | http://advantech.vo.llnwd.net/o35/www/webaccess/driver_manual/Advantech-WebAccess-Quick-Start-Guide.pdf | |
| Advantech | EKI-7659C, EKI-7657C | admin:admin | 80/tcp | industrial switch | HTTP | http://www.rts.ua/catalog/advantech/pdf/EKI-7659C_2_201316.pdf | |
| Advantech | ADAM-6200 Series | root:00000000 | 80/tcp | Intelligent Ethernet I/O Module | HTTP | http://www.bb-elec.com/Products/Manuals/ADAM-6200m-pdf.pdf | |
| Advantech | ADAM-6050W | 00000000 | I/O module | http://datasheet.octopart.com/ADAM-6050W-AE-Advantech-datasheet-32780543.pdf | |||
| Advantech | ADAM-3600-A1F | Root:00000000, Admin:00000000, User:00000000 | 80/tcp | Remote I/O Module | HTTP | https://www.proxis.ua/files/documents/UM-ADAM-3600-A1F-Ed1-EN.pdf | |
| Alcatel-Lucent | OmniSwitch 6250 | admin:switch | 80/tcp, 23/tcp | switch | HTTP, Telnet | https://dariusfreamon.wordpress.com/tag/defaults/ | |
| Allied Telesis | IE200 Series: AT-IE200-6GT, AT-IE200-6GP, AT-IE200-6FT, AT-IE200-6FP | manager:friend | terminal or terminal emulator program | Industrial Ethernet Switches | http://www.alliedtelesis.com/userfiles/file/IE200_InstallGuide_RevC.pdf | ||
| Alstom | KVGC202/EN/M/E11, MiCOM P141/P142/P143/P342/P343/P344/P345/P346/P391 | AAAA | Relays | https://www.gegridsolutions.com/alstomenergy/grid/Global/Grid/Resources/Documents/Automation/Technical%20manuals/KVGC202%20Manual%20GB-epslanguage=en-GB.pdf, https://www.gegridsolutions.com/AlstomEnergy/grid/TechnicalManuals/P14x/P14x_EN_T_C54.pdf | |||
| Argus | Argus Messenger | ArgusAdmin:masterkey | Messenger | https://dariusfreamon.wordpress.com/2015/07/11/argus-suite-multiple-default-credentials/ | |||
| Argus | Argus Address Manager | argus:argus | Address Manager Software | https://dariusfreamon.wordpress.com/2015/07/11/argus-suite-multiple-default-credentials/ | |||
| Astute Medical | ASTUTE140 Meter | 1234:1234 | analyzer | https://dariusfreamon.wordpress.com/2015/07/11/astute-medical-astute140-meter-default-user-credentials/ | |||
| B&B ELECTRONICS | CR10 v2 | root:root | 80/tcp | Industrial router | http | http://tekniska.pl/downloadfile/1400014902-1208342584-pdf | |
| B&B ELECTRONICS | Conel 4.0.1 | root:root | 80/tcp | Industrial router | http | http://conel.ru/shared/files/201502/9_411.pdf | |
| B&B ELECTRONICS | SPECTRE Router | root:root | 80/tcp | Router | http | b&b electronics SPECTRE Router.pdf | |
| B&B ELECTRONICS | ER75i/ER 75i DUO/ER 75i SL/ER75i v2 | root:root | 80/tcp | Industrial router | http | http://ec-mobile.ru/user_files/File/Conel/ER75i_Manual_RUS.pdf | |
| B&B ELECTRONICS | LR77 v2 Libratum/LR77 v2 | root:root | 80/tcp | Industrial router | http | http://www.induowireless.com/wp-content/uploads/2014/12/lr77-v2-libratum-manual.pdf, http://data.kommago.nl/files/pdf/conel-lr77_v2-handleiding.pdf | |
| B&B ELECTRONICS | UR5i v2 | root:root | 80/tcp | Industrial router | http | http://www.cd.lucom.de/vpn-industrie-router/dokumentation/handbuch/ur5iv2-guide.pdf | |
| B&B ELECTRONICS | UCR11-v2/UCR11 v2 SL | root:root | 80/tcp | Industrial router | http | http://www.induowireless.com/wp-content/uploads/2014/03/ucr11-3g-router-hspa-cdma.pdf | |
| B&B ELECTRONICS | XR5i v2E/XR5i v2/XR5i/XR5i SL | root:root | 80/tcp | Industrial router | http | http://www.cd.lucom.de/vpn-industrie-router/dokumentation/handbuch/xr5iv2e-guide.pdf | |
| B&B ELECTRONICS | ES1A | root:dbps | 80/tcp | Converter | HTTP | http://www.bb-elec.com/Products/Manuals/pn-6909-rev003_ES1A-5012m.pdf | |
| B&B ELECTRONICS | Vlinx VESR4x4 | <blank> | SERIAL SERVER | http://www.bb-elec.com/Products/Manuals/VESP211-5012m.pdf | |||
| B&B ELECTRONICS | Vlinx MESR9xx Modbus Gateway | <blank> | Modbus Gateway | https://www.manualshelf.com/manual/b-b-electronics/vlinx-mesr9xx/modbus-gateway-brochure/page-31.html | |||
| Barco | MediCal QAWeb Agent | Advanced:advanced | client application | https://dariusfreamon.wordpress.com/2015/07/10/barco-medical-qaweb-agent-default-password/ | |||
| Beckhoff Automation GmbH | CX5020 | webguest:1 | 23/tcp | PLC | Telnet | https://www.researchgate.net/publication/272420507_ICSSCADA_Security_Analysis_of_a_Beckhoff_CX5020_PLC | |
| Beckhoff Automation GmbH | TwinCAT | Administrator:1 | Software for the Windows control and automation technology | https://infosys.beckhoff.com/english.php?content=../content/1033/sw_os/html/cx1000_os_xpe_geninfo.htm&id= | |||
| Beck IPC | IPC@CHIP | PPPSERVER:, ppps:ppps | PLC | pap/chap | https://www.beck-ipc.com/files/api/scxxx/config.htm | ||
| BinTec Elmeg | BinTec X1200 II | admin:bintec, | Router | http://www.router-defaults.com/Router/BinTec--x1200-ip-password-username | |||
| BinTec Elmeg | any routers | (##unknown - means not known or any char):, ##unknown:snmp-Trap , suggested:, admin:1234, admin:password, admin:admin | Router | http://www.router-defaults.com/Router/BinTec--x1200-ip-password-username | |||
| BinTec Elmeg | BinTec R230aw | admin:funkwerk | Router | http://www.tomshw.it/forum/banda-larga/154194-router-bintec.html | |||
| BinTec Elmeg | Bintec W2002T-n | admin:funkwerk, admin:admin | WLAN Access Point for applications in rolling stocks | http://www.bintec-elmeg.com/download.php?src=portal/downloadcenter/dateien/w2002tn/documentation/Notes-default-password-standard-passwort.pdf&system_id=138324 | |||
| BK Ultrasound | bk3000 | administrator:superuser | Ultrasound System | https://dariusfreamon.wordpress.com/2015/07/12/bk-medical-aps-bk3000-ultrasound-system-default-credentials/ | |||
| Carlo Gavazzi | PowerSoft | admin:admin, user:user | modular software | https://www.gavazzionline.com/pdf/PowerSoftIMENG.pdf | |||
| CAREL | easy/easy compact/easy split, PJ32V/PJ32W/PJ32Z | 22 (access to the parameters) | electronic microprocessor controllers, plug-in electronic digital thermostat | http://www.tempatron.co.uk/resources/product/manual_79.pdf, http://www.tempatron.co.uk/resources/product/manual_77.pdf | |||
| CAREL | pCOWeb | root:froot, carel:fcarel, guest:fguest, httpadmin:fhttpadmin (ftp), admin:fadmin (http), passwordless accounts via telnet: http::48:48:HTTP users:/usr/http/root:/bin/bash, nobody::99:99:nobody:/var/lib/nobody:/bin/bash | 21/tcp, 80/tcp | communication card | FTP, HTTP | http://www.carel.com/documents/10191/0/%2B030220471/9619472f-f1c0-4ec9-a151-120aaa5e479a?version=1.0, https://packetstormsecurity.com/files/121716/CAREL-pCOWeb-1.5.0-Default-Credential-Shell-Access.html | |
| CAREL | ir33 platform: ir33, ir33 power, ir33 DIN, powercompact, powercompact small, mastercella | 22 (access to the parameters), 66 (download activation password) | integrated electronic microprocessor controllers with LED display | http://www.tempatron.co.uk/resources/product/manual_80.pdf | |||
| CAREL | Universal Infrared Series | 22 (enter and modify parameters C0, C13, 15 and 16 in addition to all “P” parameters), 77 (enter and modify all parameters) | pressure, humidity and temperature controllers | http://www.tempatron.co.uk/resources/product/manual_76.pdf | |||
| CAREL | IR33-DN33 Universale series | 77 (Setting type c, d, F parameters) | pressure, humidity and temperature controllers | http://www.temperature-house.com/cms-files/Carel_IR33_Manual_for_Warming_Oven.pdf | |||
| CAREL | pRack PR100 | user password: 0000, service password: 1234, manufacturer password: 1234 | compressor rack controller | http://www.carel-cz.cz/dokumentace/chlazeni/pRack/pRack_Quick%20guide.pdf | |||
| CAREL | humiSteam x-plus | 77 | humidifiers | http://www.airsystems.ro/assets/manual-humisteam-xplus--0300040en.pdf | |||
| CAREL | PlantVisorPRO Locale | admin:admin | 443/tcp | Plant supervision | HTTPS | http://www.alltyperefrigeration.com.au/logos/monitoring/quick_guide.pdf | |
| CAREL | PlantWatchPRO | PVRemote:PD35010 (from a remote PC via a telephone connection) | 80/tcp | supervisor for small-medium installations | HTTP | http://www.carel.co.th/documents/10191/0/%2B040000021/4b549ef7-3d35-4454-bc04-91ba26aa945d?version=1.0 | |
| CAREL | μC2SE | Direct level: <blank>, user level: 22, super user level: 11, factory level: 66 | electronic controller | http://planetaklimata.com.ua/instr/Carel/Carel_mC2SE_User_Manual_Eng.pdf | |||
| ClimateWorx International | In-Row M52 Microprocessor | 1024 (Service level) | controller | http://www.climateworxinternational.com/pdf/manuals/In_Row_Controller_User_Guide.pdf | |||
| ClimateWorx International | M52 Microprocessor | Level 1: 1024, level 2: 4321, level 3: 1234 | controller | http://www.climateworxinternational.com/pdf/manuals/m52umCT.pdf | |||
| ClinicPro | ClinicPro EMR | admin:abc123 | Electronic Medical / Health Records Software | https://dariusfreamon.wordpress.com/2015/07/11/clinicpro-default-admin-credentials/ | |||
| Compumedics | E-Series EEG, E-Series EEG/PSG, Siesta and Safiro data acquisition systems and the ProFusion EEG data acquisitionand analysis software | 0000 (security dialogue password) | Electroencephalograph Systems,data acquisition systems, HMI software | https://dariusfreamon.wordpress.com/2014/08/29/compumedics-software-default-password/ | |||
| Contemporary Control Systems | BASRT-B | admin:admin | 80/tcp | Router | http | http://www.ccontrols.com/pdf/TD0712000I2.pdf | |
| Datex-Ohmeda | S/5 Light Monitor | 16-4-34 | portable vital signs monitor | https://dariusfreamon.wordpress.com/2014/08/28/datex-ohmeda-s5-light-monitor-default-installservice-menu-password/ | |||
| Datasensor | UR5i/UR5i SL | root:root | 80/tcp | Router | http | http://datasensor.de/sites/datasensor.de/files/datasheets/UR5i_m_e.pdf | |
| Deif | AWC 500 | root:deif7800 (administrator), default:1234 (user) | Advanced Wind turbine Controller | http://www.deifwindpower.com/Files/Files/Documentation/Products/AWC-500/4189340733_AWC_500_Getting_started.pdf | |||
| Digi | DC-ME-01T-S | root:dbps | Networking Modules | http | http://www.digi.com/support/forum/13553/digi-connect-me-default-password | ||
| Digi | Digi Connect SP,Digi Connect Wi-SP,Digi Connect ME,Digi Connect ME 4 MB,Digi Connect Wi-ME,Digi Connect EM,Digi Connect Wi-EM | root:dbps | 80/tcp | Network Device Server Module | http | http://ftp1.digi.com/support/documentation/90000565_P1.pdf | |
| Digi | Digi Connect ES 4/8 SB with Switch, Digi Connect ES 4/8 SB | root:dbps | 80/tcp | Concentrator | http | http://ftp1.digi.com/support/documentation/90000565_P1.pdf | |
| Digi | ConnectPort TS 4x4, ConnectPort TS 4x2, ConnectPort TS W, ConnectPort TS 8, ConnectPort TS 8 MEI, ConnectPort TS 16 | root:dbps | 80/tcp | Terminal Server | http | http://ftp1.digi.com/support/documentation/90000565_P1.pdf | |
| Digi | Digi Connect WAN, Digi Connect WAN GPRS, Digi Connect WAN GSM-R, Digi Connect WAN VPN, Digi Connect WAN IA, Digi Connect WAN 3G, Digi Connect WAN 3G IA, Digi Connect WAN 4G | root:dbps | 80/tcp | Industrial router | http | http://www.acspl.com.au/Manuals/digi_Wan.pdf | |
| Digi | Digi TransPort WR21/WR44 | username:password | 80/tcp | Industrial router | http | http://ftp1.digi.com/support/documentation/transport/assets/guides/IG_Digi_WR21.pdf | |
| Digi | Digi CM | root:dbps | console port (9600, 8, N, 1) | Industrial router | http://ftp1.digi.com/support/documentation/90000300_E.pdf | ||
| Digi | DigiOne IAP Serial | root:dbps | 80/tcp | Gateway | http | http://web-material3.yokogawa.com/IMMW100EIP.pdf | |
| Echelon | i.LON SmartServer | for ftp and lns servers: ilon:ilon | Programmable Modules | ftp, L2TP | http://www.unicom-bg.com/pdf/systemintegration/iLONproducts/i.LON_SmartServer_Freely_Programmable_Modules_User_Guide.pdf | ||
| Echelon | i.LON SmartServer, i.LON SmartServer 2.0, i.LON 600, i.LON 100e4 | ilon:ilon | 80/tcp | Building Energy Management Solution, LonWorks/IP Server, Internet Server | HTTP | https://dariusfreamon.wordpress.com/2013/05/10/echelon-i-lon-defaults/ | |
| Echelon | LumInsight | Echelon:echeloncorp | Central Management System | http://www.echelon.com/assets/blt3db1ad5ba909f610/LumInsight%20CMS%20Installation%20Guide_078-1059-01C.pdf | |||
| Electro Industries/GaugeTech | Nexus 1500+, Nexus 1500 | anonymous:anonymous | 80/tcp | Power Quality Meter | HTTP | http://www.electroind.com/products/Nexus_1500+/pdf/manuals/Nexus%201500+%20Power%20Quality%20Meter%20User%20Manual%20V.1.01_E154713.pdf, http://www.electroind.com/products/Nexus_1500/pdf/manuals/Nexus%201500%20Transient%20Recording%20Power%20Quality%20Revenue%20Meter%20User%20Manual%20V.1.12_E154701.pdf | |
| Electro Industries/GaugeTech | Communicator EXT 3.0 | eignet:inp100 | 80/tcp | Power Monitoring Software | HTTP | http://www.electroind.com/pdf/11_13_12_pdf/E107707_ComEXT_Manual.pdf | |
| Emerson | AMS Suit | admin:<blank>, sa:42Emerson42Eme (SQL Server) | diagnostic software | http://www2.emersonprocess.com/siteadmincenter/PM%20Asset%20Optimization%20Documents/ProductReferenceAndGuides/amsdm_ru_quickinstallv12.pdf, http://www2.emersonprocess.com/siteadmincenter/PM%20Asset%20Optimization%20Documents/ProductReferenceAndGuides/amsdm_ru_installguide13.pdf | |||
| Emerson | DeltaV Digital Automation System | Administrator:deltav | Automation System | http://www.chem.mtu.edu/chem_eng/current/new_courses/CM4120/2009/Getting%20Started.pdf | |||
| Emerson | Liebert IntelliSlot Web Card | Liebert:Liebert, User:User | 23/tcp | Web Card | telnet | http://www.emersonnetworkpower.com/documentation/en-us/products/monitoring/documents/sl-52615.pdf | |
| Emerson | Liebert OpenComms Web Card | Liebert:Liebert | 80/tcp | Web Card | HTTP | http://www.emersonnetworkpower.com/documentation/en-us/products/monitoring/documents/sl-52610.pdf | |
| Emerson | Smart Wireless Gateway 1420 | admin:default, maint:default, oper:default, exec:default | 80/tcp | Wireless Gateway | http | http://www2.emersonprocess.com/siteadmincenter/PM%20Rosemount%20Documents/00809-0200-4420.pdf | |
| Emerson | Smart Wireless Navigator | for the Windows log in Administrator:navigator, for Smart Wireless Navigator log in Supervisor:Admin, User1:Password1, User2:Password2, User3:Password3 | stand-alone network infrastructure management tool | http://www2.emersonprocess.com/siteadmincenter/pm%20rosemount%20documents/00809-0100-4423.pdf | |||
| Emerson | Network Power MPH2 Rack PDU | admin:admin | 80/tcp | Rack PDUs | http | https://community.emerson.com/networkpower/support/avocent/power/mph2/m/mediagallery/3093 | |
| Emerson | UL33 UPS | 123456 | UPS | Serial | http://www.emersonnetworkpower-partner.com/ArticleDocuments/4091/UL33%20User%20Manual%20Communication.doc.aspx | ||
| Emerson | Control Link Refrigeration System Controller | 0000 | Controller | http://foodservice.structuralconcepts.com/media/com_sccmanager/temp-controller-info/emerson-control-link-cpc-controller.pdf | |||
| Emerson | UltraSite | User 01:100, User 05:200, User 09:300, Engineer:400 | Software | http://www.emersonclimate.com/Documents/Retail%20Solutions/Manuals/0261004Rev1.pdf | |||
| Emerson | Avocent ACS 6000 Advanced Console Server | admin:avocent, root:linux | Console Server | console port, with Telnet, SSH | http://pcs.mktg.avocent.com/@@content/manual/590767501h.pdf | ||
| Emerson | ROCLINK 800 | LOI:1000 | Software | Console | http://www.documentation.emersonprocess.com/groups/public/documents/instruction_manuals/d301159x012.pdf | ||
| Emerson | ControlWave Micro Quick | for download project:, SYSTEM:666666 | PLC | http://www.documentation.emersonprocess.com/groups/public/documents/users_guide/d301425x012.pdf | |||
| Emerson | IP-KVM Avocent MergePoint Unity | Admin:blank | Switch | local, HTTP | http://community.emerson.com/networkpower/support/avocent/kvmip/mpunity/w/wiki-mergepoint-unity/363.default-user-name-and-password-for-the-mergepoint-unity-kvm-over-ip-appliance | ||
| Emerson | Ovation DCS | wdpf | Switch for Distributed Control System | Telnet | https://supportforums.cisco.com/sites/default/files/legacy/0/3/9/11930-cs2.txt | ||
| Emerson | Ovation DCS | SNMP community string: wdpfRO | Switch for Distributed Control System | SNMP | https://supportforums.cisco.com/sites/default/files/legacy/0/3/9/11930-cs2.txt | ||
| Endress+Hauser | Fieldgate FXA520 | super:super | 80/tcp | Gateway for remote monitoring and diagnosis | HTTP | https://portal.endress.com/wa001/dla/5000241/6638/000/03/BA00051SEN_1514.pdf | |
| Endress+Hauser | Fieldgate Viewer | admin:0000 | HMI software | https://dariusfreamon.wordpress.com/2013/10/15/endresshauser-fieldgate-viewer-default-credentials/ | |||
| ENTES | EMG-10, EMG-02 , EMG-12 | emg12 (for EMG12), emg10 (for EMG10), emg02 (for EMG02) | 80/tcp | MODBUS Gateway | http | http://www.entes.com.tr/dosyalar/EMG_Series_EN-ver_2_2.pdf | |
| ENTES | DTR-10, MCB-125/126 | 0000 | time relay | http://www.entes.com.tr/dosyalar/DTR-10%20EN%20A5299%20R2.pdf, http://www.entes.com.tr/dosyalar/mcb-125-126%20EN_.pdf | |||
| ENTES | MPR-53CS | 0000 | network analyzer | http://www.entes.com.tr/dosyalar/MPR_53CS_ing_A4396_R2%20.pdf | |||
| ENTES | GEM-05/GEM-10/10SH | gem10 | 80/tcp | GPRS/Modbus Gateway | HTTP | http://www.produktinfo.conrad.com/datenblaetter/125000-149999/128714-an-01-en-ENTES_EPM_04C_DIN_DIGITALMULTIMETER.pdf | |
| ENTES | ENTBUS PLUS | admin:1234 | Energy Management Software | http://www.entes.com.tr/dosyalar/ENTBUS%20Plus_Client_EN.pdf | |||
| ENTES | EPM-04/04C/04CS | 0000 | MULTIMETER | http://www.produktinfo.conrad.com/datenblaetter/125000-149999/128714-an-01-en-ENTES_EPM_04C_DIN_DIGITALMULTIMETER.pdf | |||
| ENTES | MPR-SW | admin:<blank> | Monitoring & Reporting Software | http://tde-instruments.de/images/stories/produkte/MPR-SW2_Software_fuer_Fernueberwachung/entes_mpr-sw2-software-instruction_manual.pdf | |||
| eWON | all | adm:adm | 80/tcp | Router | http | http://ewon.biz/sites/default/files/aug-004-0-en-ewon_getting_started.pdf | |
| Falcon | USHA | USHA:admin | 80/tcp | UPS SNMP HTTP AGENT | HTTP | https://dariusfreamon.wordpress.com/2016/01/28/falcon-usha-ups-snmp-http-agent-default-admin-credentials/ | |
| General Electric Intelligent Platforms | IC695PNC001 | admin:system | 23/tcp (telnet) or USB | PROFINET Controller | telnet | http://platforma.astor.com.pl/files/getfile/id/6314 | |
| General Electric Intelligent Platforms | IC695ECM850 | admin:system | 23/tcp (telnet) or USB | IEC 61850 Client | telnet | http://platforma.astor.com.pl/files/getfile/id/6314, as referenced by http://www.pdfsupply.com/pdfs/gfk-2849.pdf | |
| General Electric Intelligent Platforms | IC695ETM001, IC695CPE305, IC695CPE310, IC695CPE330, IC698ETM001, IC698CPE010, IC698CPE020, IC698CRE020, IC698CPE030, IC698CPE040, IC698CRE030, IC698CRE040 | system | 18245/udp | Ethernet module/programmable controller | http://platforma.astor.com.pl/files/getfile/id/7823 | ||
| General Electric Intelligent Platforms | IC698CPE030, IC698CPE040, IC698CRE030, IC698CRE040 | user:system | 21/tcp | Programmable controller with built-in web server | ftp | http://platforma.astor.com.pl/files/getfile/id/9043 | |
| General Electric Healthcare | FASTlab Synthesizer | Admin:admin | synthesizer | https://dariusfreamon.wordpress.com/2015/07/12/ge-healthcare-fastlab-synthesizer-default-credentials/ | |||
| General Electric Healthcare | TRACERlab FX2 devices (model C, MeI and N) | admin:tracerlab (physical access required) | Synthesis module | https://dariusfreamon.wordpress.com/2015/07/12/ge-healthcare-tracerlab-fx2-default-admin-credentials/ | |||
| General Electric Healthcare | TRACERlab FX2 M | tracerlab:tracerlab (for remote access), admin:tracerlab | chemistry synthesizer | https://dariusfreamon.wordpress.com/2015/07/12/ge-healthcare-tracerlab-fx2-m-multiple-default-credentials/ | |||
| General Electric Healthcare | HiSpeed CT/i, Lightspeed QX/i | root:#bigguy, ctuser:4$apps | Computed Tomography Scanner | https://dariusfreamon.wordpress.com/2014/09/04/ge-medical-systems-hispeed-cti-system-multiple-default-accounts/ | |||
| General Electric Healthcare | Discovery CT590 RT, Optima CT580 | root:#bigguy | Computed Tomography Scanner | https://dariusfreamon.wordpress.com/2014/09/04/ge-medical-systems-hispeed-cti-system-multiple-default-accounts/ | |||
| General Electric Healthcare | Datex-Ohmeda Engström Ventilator | 23-17-21 (Super User), 34-22-14 (service-level) | Carestation Ventilators | http://static.medonecapital.com/manuals/techManuals/Datex-Ohmeda-Engstrom-VentilatorTechnical-Manual.pdf | |||
| General Electric Digital Energy | SNMP/Web Interface | GE:GE (Telnet, HTTP), public (SNMP community string) | 23/tcp, 80/tcp, 25/tcp | SNMP/Web Interface | Telnet, HTTP, SNMP | http://www.lenz.pl/files/product/17678774a663fb06a1068b6cc0342292.pdf | |
| General Electric | SymDec 4, WebServer, SymNav | Software: admin:admin, 12345 (Log In Password), Hardware: 0000 (Advanced Menu Password), 8111 (Factory Password), 1111 (Ethernet Access Reset Password), 2222 (DDNS Password) | 80/tcp | Video Streaming Recorder | HTTP | http://static.interlogix.com/library/0150-0304c_symdec_4_uman.pdf | |
| Heatmiser | Netmonitor | admin:admin | 80/tcp | gateway between the outside world and heating system | HTTP | http://www.thefloorheatingwarehouse.co.uk/acatalog/netmonitor_user_v3.pdf | |
| Helmholz Systeme | NETLink PRO HW 1-1a-1 and FW 1. 54 and higher | NETLink PRO PoE:admin | Ethernet Gateway for MPI/PROFIBUS | HTTP | https://www.helmholz.com/dnl/NETLink_PRO_PoE_QSG_v2_en.pdf | ||
| Hirschmann | RS20/RS30, MICE | user:public, admin:private | 80/tcp | Switch | http | http://www.wwsinternational.com.au/Hirschmann/pdf/quickstart.pdf;, Hirschmann MICE.pdf | |
| Hirschmann | RSP 20/25/30/35 | user:public, admin:private | 23/tcp (telnet) | Industrial router | telnet | http://www.prosoft.ru/cms/f/456864.pdf | |
| Hirschmann | MACH 4000 Family/MACH 1000 Family/MACH 100 Family/MACH 4002 Family/MACH104 Family Full Gigabit/MACH 1040 Family Full Gigabit | user:public, admin:private | Industrial router | Hirschmann MACH1040 Full Gigabit.pdf, Hirschmann MACH4002 Family.pdf, Hirschmann MACH1000 Family.pdf, Hirschmann MACH4000 Family.pdf, http://www.industrialcomms.co.uk/images/pdf/IG_MACH104_02_1210_en.pdf, http://www.industrialcomms.co.uk/images/pdf/IG_MACH100_03_0709_en.pdf | |||
| Hirschmann | OCTOPUS 8M..., OCTOPUS 16M..., OCTOPUS 24M… | user:public, admin:private | 23/tcp | Industrial router | telnet | https://www.neteon.net/media/downloads/IG_Octopus8M16M24M_PoETrain_02_0708_en_1.pdf | |
| Hirschmann | EAGLE 20 | admin:private, user:public | 443/tcp | Industrial ETHERNET Firewall | HTTPS | https://dariusfreamon.wordpress.com/2013/09/05/hirschmann-automation-and-control-eagle-20-defaults/ | |
| Hitachi | EUB-550 | Service Tools:SERVICETOOL | Ultrasound Diagnostic Scanner | https://dariusfreamon.wordpress.com/2014/08/25/hitachi-eub-5500-ultrasound-diagnostic-scanner-default-password/ | |||
| Hitachi | Web Controller | admin:1111 | 80/tcp | controller | HTTP | http://www.fhpsa.com/01_Biblioteca/03_Manuales/EH-W_NJI441E(X).pdf | |
| HollySys Automation Technologies | LK SERIES PLC | FTP blank, Telnet blank | 21/tcp, 23/tcp | PLC | FTP, Telnet | http://plcscan.org/blog/2014/12/hollysys-lk-series-plc-system-default-password-vulnerability/ | |
| Honeywell | Honeywell XL | Guest:guest, SysAdmin:honey | 80/tcp | Controller | HTTP | ||
| Honeywell | Alerton BCM-WEB | pass | BACtalk control module, Web server and Configurator CD | https://dariusfreamon.wordpress.com/2015/05/01/honeywell-alerton-bcm-web-default-admin-credentials/ | |||
| Honeywell | NetAXS | admin:admin | 443/tcp | access control unit | HTTPS | https://www.honeywellaccess.com/documents/UserManual_for_Release_3-800-04410-A.pdf | |
| IBM | 2210 | def:trade | Multiprotocol Router | http://www.governmentsecurity.org/_/articles/default-logins-and-passwords-for-networked-devices.html | |||
| Kostal Solar | PIKO-Inverter 3.0, 3.6, 4.2, 5.5, 7.0, 8.3, 10.1, PIKO BA Storage System | pvserver:pvwr | 80/tcp | solar inverter, storage system | HTTP | http://www.kostal-solar-electric.com/Standalone/MediaDispositionViewer.aspx?medid=7a7356e144fd48b0b8557c4249cb35fd, https://dariusfreamon.wordpress.com/2014/01/15/kostal-solar-piko-ba-storage-system-web-interface-default-admin-credentials/ | |
| Lantronix | EDS-MD 4, EDS-MD 8, EDS-MD 16 | admin:PASS | 80/tcp | Medical Device Server | HTTP | https://dariusfreamon.wordpress.com/2015/07/11/lantronix-eds-md-medical-device-server-web-interface-default-admin-credentials/ | |
| LOYTEC Electronics | L-DALI DALI Light Controller, L-INX Automation Server, L-GATE Universal Gateway, L-IP CEA-709/IP Router, L-VIS, LIOB-10x I/O Module, LIOB-x5x I/O Module, LIP-ME20X L-IP BACnet Router, LWEB-802, LWEB-803, LWEB-900 Building Management System | admin:loytec4u | 80/tcp | Multiple Devices | HTTP | https://dariusfreamon.wordpress.com/2016/02/01/loytec-electronics-multiple-devices-web-interface-default-admin-credentials/ | |
| LOYTEC Electronics | L-Proxy CEA-709 Gateway | admin:admin | 80/tcp | Gateway | HTTP | https://dariusfreamon.wordpress.com/2016/02/01/loytec-electronics-multiple-devices-web-interface-default-admin-credentials/ | |
| Metrobility | NetBeacon Element Management Software | guest:guest, admin:admin, root:root | 23/tcp | HMI Software | Telnet | https://dariusfreamon.wordpress.com/2014/09/02/netbeacon-element-management-software-multiple-default-credentials/ | |
| Mitsubishi | PLC QnUCPU QnUDVCPU | MELSEC:MELSEC | 21/tcp | PLC | FTP, HTTP | http://dl.mitsubishielectric.com/dl/fa/document/manual/plc/sh080811eng/sh080811engp.pdf | |
| Mitsubishi | PLC QnUCPU QnUDE(H)CPU | QNUDECPU:QNUDECPU | 21/tcp | PLC | FTP, HTTP | http://dl.mitsubishielectric.com/dl/fa/document/manual/plc/sh080811eng/sh080811engp.pdf | |
| Mitsubishi | MES3-255C-EN | ecoV:ecopass, guest:user | Web server | https://dariusfreamon.wordpress.com/2014/02/28/mitsubishi-energy-saving-data-collecting-server-ecowebserver-iii-mes3-255c-en-default-credentials/ | |||
| Moxa | AirWorks AWK-3131-RCC | admin:root | 80/tcp | Industrial 802.11n wireless AP/bridge/client | HTTP | http://www.moxa.com/doc/man/AWK-3131-RCC_UM_1e.pdf | |
| Moxa | Railway Remote I/O (ioLogik E12xx, ioLogik E15xx) | HTTP on Port 9020: 1)none:root, 2)none:none | 9020/tcp | Remote Ethernet I/O | HTTP | http://www.toolswatch.org/2013/02/new-scada-default-passwords-added-to-dpe-xml-database/ | |
| Moxa | Cellular Micro RTU Controller (ioLogik W53xx, ioLogik) | administrator:blank, Telnet on port 9900 / 9000: root:root | 9900/9000/tcp | micro RTU controller | telnet or serial console | http://www.toolswatch.org/2013/02/new-scada-default-passwords-added-to-dpe-xml-database/ | |
| Moxa | VPort 461 Industrial Video Encoder | admin:admin, <none>:<none> | Industrial Video Encoder | telnet | http://www.moxa.com/doc/man/VPort_461_UM_2e.pdf | ||
| Moxa | IA240/241 Embedded computer | telnet root:root, FTP root:blank, PPP root:root, serial console root:root | Embedded computers are designed for industrial, automation applications | Telnet, FTP, PPP, serial console | http://www.toolswatch.org/2013/02/new-scada-default-passwords-added-to-dpe-xml-database/ | ||
| Moxa | OnCell Central Manager | admin:admin | 8080/tcp | Software | HTTP | http://www.moxa.ru/files/manuals_modems/oncell_central_manager_users_manual_v1.pdf | |
| Moxa | EDS-508A/505A Series | admin:<none> | Switch | telnet or serial console | http://www.moxa.com/doc/man/eds-508a_505a_um_4e.pdf | ||
| Moxa | OnCell G3100 Series | HTTP admin:admin, HTTP Admin:Keep <blank>, PAP admin:<blank> | 80/tcp | cellular IP gateways | Telnet, PAP | http://www.moxa.com/doc/man/OnCell_G3100_Series_Users_Manual_v7.pdf | |
| Netcomm Wireless | 3G21WB (BigPond Firmware), 3G9WB (BigPond Firmware), N3G001W (Netcomm Firmware), NB14WN (Netcomm Firmware), NB5 (Netcomm Firmware), NB5Plus4 (Netcomm Firmware), NB6Plus4 (Netcomm Firmware), NB6Plus4W (Netcomm Firmware), NNB7 (Netcomm Firmware), NB9WMAXX (Netcomm Firmware), NP804N (Netcomm Firmware) | admin:admin | Router | http://www.pcwintech.com/default-router-modem-passwords2 | |||
| Netcomm Wireless | NB1300 Plus 4 (Netcomm Firmware), NP803N (Netcomm Firmware) | admin:password | Router | http://www.pcwintech.com/default-router-modem-passwords2 | |||
| NOVUS AUTOMATION | SuperView | superview:superview | SCADA | http://www.novusautomation.com/downloads/Arquivos/v29x_a_manual_superview_english.pdf | |||
| NOVUS Automation | AirGate-3G | admin:admin | Dual SIM Industrial Cellular VPN Router | https://dariusfreamon.wordpress.com/2016/02/02/novus-airgate-3g-dual-sim-industrial-cellular-vpn-router-default-admin-credentials/ | |||
| NOVUS Automation | N1040, N480D, N960, N1020, N1040i, N1540, N2000, N3000 and N120 | 1111 (ACESS PASSWORD), 9 3 2 1 (MASTER PASSWORD) | Temperature Controller | https://dariusfreamon.wordpress.com/2015/04/18/novus-n1040-controller/ | |||
| Nuance | Dragon Medical 360 Network Edition | admin:password | 80/tcp | Medical Speech Recognition Software Solutions | HTTP | https://dariusfreamon.wordpress.com/2015/07/11/dragon-medical-360-network-edition-nuance-management-console-default-admin-credentials/ | |
| Omron IA | CJ1M CPU Units with Ethernet Functions | for http: ETHERNET, for ftp: CONFIDENTIAL | 80/tcp (http), 21/tcp (ftp) | PLC | http, ftp | http://omronkft.hu/nostree/pdfs/plc/cs1_cj1/w441-e1-03+cj-series-ethernetfunc+opermanual.pdf | |
| Omron | NS-Series Programmable Terminals Web Interface (NS12-TS01-V2, NS10-TV01-V2, NS8-TV01-V2, NS5-SQ11-V2, NS5-TQ11-V2 and NS5-MQ11-V2) | default:default | 80/tcp | Programmable Terminals | HTTP | http://www.omronkft.hu/nostree/pdfs/ns/v100-e1-01.pdf | |
| Ouman | EH-net server | admin:admin | HMI Software | http://docplayer.fi/509891-Palvelin-eh-net-kayttoonotto-ja-yllapito-www-ouman-fi.html | |||
| Phasefale Controls | JouleTemp | admin:pass | 80/tcp | PLC | HTTP | http://phasefale.com.au/wp-content/themes/twentythirteen/docs/JouleRange/JouleTemp/jt_instruction_iss8.pdf | |
| Phoenix Contact | Logic+ | admin:admin | 80/tcp | Software | http | https://www.phoenixcontact.com/assets/downloads_ed/global/web_dwl_technical_info/52005213_EN.pdf | |
| PIPS Technology | AUTOPLATE | <blank> (Telnet), wl_test:wl_test, vesstore:vesstore, ftp_boot:ftp_boot (FTP) | 23/tcp, 21/tcp | license plate recognition system | Telnet, FTP | https://dariusfreamon.wordpress.com/2014/02/19/pips-technology-autoplate-automatic-license-plate-recognition-alpr-multiple-vulnerabilities/ | |
| Prosoft Technology | ICX30-HWC | admin:password | 80/tcp | Industrial Cellular Gateway | HTTP | http://www.prosoft-technology.com/content/download/8772/168219/version/9/file/ICX30_HWC_User_Manual.pdf | |
| Rockwell Automation / Allen-Bradley | 1756-EN2TSC | Administrator:admin | 80/tcp | EtherNet/IP communication module | HTTP | http://literature.rockwellautomation.com/idc/groups/literature/documents/um/enet-um003_-en-p.pdf | |
| Rockwell Automation / Allen-Bradley | 1734-AENT | admin:password | 80/tcp | I/O Adapter | HTTP | http://literature.rockwellautomation.com/idc/groups/literature/documents/um/1734-um011_-en-p.pdf | |
| Rockwell Automation / Allen-Bradley | 1756-EWEB, 1768-EWEB | Administrator:<none> | 80/tcp | Web Server Module | HTTP | http://literature.rockwellautomation.com/idc/groups/literature/documents/um/enet-um527_-en-p.pdf | |
| Rockwell Automation / Allen-Bradley | 9300-RADES | HTTP: blank:ZYPCOM, Telnet: blank:ZYPCOM, FTP: uploader:ZYPCOM, CHAP/PAP: ppp_user:ZYPCOM | 80/tcp, 23/tcp, 21/tcp | Industrial Modem | HTTP, Telnet, FTP, CHAP/PAP | http://literature.rockwellautomation.com/idc/groups/literature/documents/um/gmsc10-um004_-en-e.pdf | |
| Rockwell Automation / Allen-Bradley | 9300-8EDM | HTTP: blank:ZYPCOM, Telnet: blank:ZYPCOM, FTP: uploader:ZYPCOM | 80/tcp, 23/tcp, 21/tcp | Industrial Switch | HTTP, Telnet, FTP | http://literature.rockwellautomation.com/idc/groups/literature/documents/um/gmsc10-um003_-en-e.pdf | |
| Rockwell Automation / Allen-Bradley | MicroLogix 1400 / MicroLogix 1100 Embedded Web Server | guest:guest, administrator:ml1400 (MicroLogix 1400), administrator:ml1100 (MicroLogix 1100) | 80/tcp | Web Server | http | http://literature.rockwellautomation.com/idc/groups/literature/documents/um/1766-um002_-en-p.pdf, http,http://literature.rockwellautomation.com/idc/groups/literature/documents/um/1763-um002_-en-p.pdf | |
| Rockwell Automation / Allen-Bradley | PanelView Plus 6 Graphic Terminals, Firmware 6.10 or later/, PVPlus 6 | password | SCADA | Desktop access | http://www.manualsdir.com/manuals/580848/rockwell-automation-2711p-xxxx-panelview-plus-6-terminals-user-manual.html?page=54 | ||
| SAMSON GROUP | TROVIS 5590 Web Module | To read data 1111:1111, To change data 4444:4444 | Web Module | http://www.samsongroup.net/trovis-app/en-tv-page-102.htm | |||
| Samsung | Integrated Management System DMS | root:rkwjsdusrnth | Data Management Server | http://www.tenable.com/plugins/index.php?view=single&id=53878 | |||
| Samsung | Integrated Management System S-NET mini | DMS Connection: 0000 or 1234 | S-NET IMS | http://dvmdownload.com/controls/central-control-options/mst-s3w/technical-tip/SNET%20MINI%20MST-S3W%20SETUP_1%2017%202012.pdf | |||
| Schneider Electric | PowerLogic Series 800 Power Meter | 0000 | PLC | http://www.powerlogic.com/literature/63230-500-282A1_PM8_Install_Guide.pdf | |||
| Schneider Electric | PowerLogic ION7550 / ION7650 / ION8650 Energy and power meter | 0 | Energy and power meter | http://www2.schneider-electric.com/library/SCHNEIDER_ELECTRIC/SE_LOCAL/APS/209510_35F6/8650_Install_Guide.pdf, http://azzo.com.au/wp-content/uploads/2015/08/ION7550-RTU-UserGuide.pdf | |||
| Schneider Electric | PowerLogic Ethernet Gateway EGX300 / EGX100 | Administrator:Gateway | 80/tcp | Integrated gateway-server | http | http://azzo.com.au/wp-content/uploads/2015/05/PowerLogic-EGX300-Users-Guide.pdf | |
| Schneider Electric | POWERLOGIC EGX200 / EGX400 with firmware version 5.5 or higher | Administrator:admin, User 1:master, User 2:engineer, User 3:operator | 80/tcp | gateway-server | http | http://www.powerlogic.com/literature/63230-314-208A3.pdf | |
| Schneider Electric | Modicon Quantum | ftpuser/password, qbf77101/hexakisoctahedron, USER:USER | 21/tcp, 23/tcp, 80/tcp | PLC | HTTP, FTP, Telnet | http://www.digitalbond.com/tools/basecamp/schneider-modicon-quantum/, http://www.schneider-electric.cn/downloads//85257689000007EE/All/01507367599A9DC985257871005F4B3D/$File/EIO0000000121EN.pdf | |
| Schneider Electric | Modicon M340 for Ethernet | ntpupdate:ntpupdate (Using an FTP client, store your rules in the file:, /FLASH0/wwwroot/conf/NTP/customrules), USER:USER (FTP Setup page via HTTP, HTTP credentials), sysdiag:factorycast@schneider (FTP) | 21/tcp, 80/tcp | PLC | FTP, HTTP | https://dariusfreamon.wordpress.com/2013/12/08/schneider-modicon-m340-for-ethernet-multiple-default-credentials/, https://github.com/ITI/ICS-Security-Tools/blob/master/configurations/passwords/ics-default-passwords.csv | |
| Schneider Electric | Modicon Premium | FTP: sysdiag:factorycast@schneider, HTTP: USER:USER | 21/tcp, 80/tcp | PLC | FTP, HTTP | https://github.com/ITI/ICS-Security-Tools/blob/master/configurations/passwords/ics-default-passwords.csv | |
| Schneider Electric | PM8000, PM8240, PM8243, PM8244 | Physical: 0, FTP: 8000:<display password> | 21/tcp, 80/tcp | PLC | FTP, HTTP | http://www2.schneider-electric.com/sites/corporate/en/support/faq/faq_main.page?page=content&country=APS_GLOBAL&lang=en&locale=en_US&id=FA243275&redirect=true | |
| Schneider Electric | TSX ETG 1000 | HTTP Server, PAP Protocol: USER:USER, FTP: wsupgrade:wsupgrade, Serial Connection: Administrator:Gateway | 21 TCP | PLC | FTP, PAP, HTTP | http://www.is-com.ru/files/net_tsxetg1000.pdf | |
| Schneider Electric | ETG100 | Administrator:Gateway | PLC | http://www.schneider-electric.co.in/sites/india/en/support/faq/main_faq.page?page=content&country=IN&lang=en&id=FA138738&locale=en_US&redirect=true | |||
| Schneider Electric | M258 | adm:adm | 80/tcp | PLC | http | http://ewon.biz/sites/default/files/aug-054-0-en-remote_access_for_schneider_m258_plcs.pdf | |
| Schneider Electric | Quantum NOE 771 xx | pcfactory:pcfactory, loader:fwdownload, ntpupdate:ntpupdate, sysdiag:factorycast@schneider, test:testingpw, webserver:webpages, fdrusers:sresurdf, nic2212:poiuypoiuy, nimrohs2212:qwertyqwerty, nip2212:fcsdfcsd, noe77111_v500:RcSyyebczS (password hashed), AUTCSE:RybQRceeSd (password hashed), AUT_CSE:cQdd9debez (password hashed), target:RcQbRbzRyc (password hasshed), FTP and HTTP Service: USER:USERUSER, USER:USER, ftpuser:ftpuser (FTP) | 21/tcp, 80/tcp | Ethernet Modules | ftp, http | https://igate.alamedaelectric.com/Modicon%20Documents/PLC%20Quantum%20PLC%20NOE771xx%20User%20Manual%20v5.0.pdf | |
| Siemens | Simatic S7-300 (pre-2009 versions) | Hardcoded password: Basisk:Basisk | 23/tcp, 80/tcp | PLC | telnet. Http | http://www.wired.com/2011/08/siemens-hardcoded-password/ | |
| Siemens | S7-1200 / S7-1500 | admin:blank | 80/tcp | PLC | HTTP | https://www.dmcinfo.com/latest-thinking/blog/id/8567/siemens-s7-1200-web-server-tutorial--from-getting-started-to-html5-user-defined-pages | |
| Siemens | Scalance X-200, W788-1PRO, W788-2PRO, etc. | admin:admin (HTTP), user:user (HTTP), siemens:siemens (FTP) | tcp/80 | Industrial Wireless LAN, Industrial Ethernet Switches | HTTP, FTP | http://dariusfreamon.wordpress.com/2013/10/02/siemens-scalance-x-industrial-ethernet-switches/, https://cache.industry.siemens.com/dl/files/728/25508728/att_4008/v1/BA_SCALANCE-X-200_76.pdf, https://www.acunetix.com/vulnerabilities/network/vulnerability/siemens-scalance-default-credentials/ | |
| Siemens | Synco living Web server OZW772 V2.0 | Administrator:Password | 80/tcp | Web-server | HTTP | http://www.toolswatch.org/2013/02/new-scada-default-passwords-added-to-dpe-xml-database/ | |
| Siemens | Siemens WinCC 7.x | winccd:winccpass, wincce:winccpass, DMUser:Data&Pass, Administrator:Administrator | HMI Software | http://www.toolswatch.org/2013/02/new-scada-default-passwords-added-to-dpe-xml-database/ | |||
| Siemens | Ruggedcom RMC30 | admin:admin, operator:operator, guest:guest | 80/tcp | Industrial router | HTTP | http://www2.schneider-electric.com/resources/sites/SCHNEIDER_ELECTRIC/content/live/FAQS/239000/FA239168/en_US/ROS_RMC30_User-Guide_EN.pdf | |
| Siemens | RUGGEDCOM ROX II for RX1500, RX1501, RX1510, RX1511, RX1512 | root:admin (service), admin:admin (administrator), oper:oper (operator), guest:guest (guest) | Ethernet Switches Layer 3 / Routers | https://cache.industry.siemens.com/dl/files/287/81194287/att_837966/v1/ROXII_v2.6_RX1500_User-Guide_CLI_EN.pdf | |||
| Siemens | RuggedSwitch RS8000 / RS1600 / RS900 | admin | Industrial router | RS232 | http://www.techsalesnw.com/oldwebsite/products/ethernet/rc_files/RuggedSwitch%20User%20Guide%20v1.5.1.pdf | ||
| Siemens | Siemens ST950 | root:zP2wxY4uE | 161/udp | Intersection controller | SNMPv3 | http://www.siemens.co.uk/traffic/en/index/productssolutionsservices/signalsandcontrollers/st950.htm | |
| Siemens | Siemens Climatix | Level 6 End users: 1000 (Physical), Level 4 Service operator: 2000 (Physical), Level 2 OEM: 6000 (Physical), Web: ADMIN:SBTAdmin! | 80/tcp | PLC | HTTP | http://www.ivprodukt.se/documents/ivprodukt/documents/styr%20climatix/basis%20document%20climatix%20control%20system%20bdcx.100820.01.gb.pdf | |
| Siemens | Sicam SGU | 642935177 | 80/tcp | RTU | HTTP | http://w3.siemens.com/smartgrid/global/en/products-systems-solutions/substation-automation/remote-terminal-units/Pages/sicam-sgu.aspx | |
| Siemens | Sicam SGU | admin@root:charleM!800 | 9443/tcp | RTU | HTTPS | http://w3.siemens.com/smartgrid/global/en/products-systems-solutions/substation-automation/remote-terminal-units/Pages/sicam-sgu.aspx | |
| Siemens | SC 7000 / SC 9000XL | 4712 (passcode, physical access required) | Patient Monitors Service | https://dariusfreamon.wordpress.com/2015/07/12/siemens-sc-7000-sc-9000xl-patient-monitors-default-admin-passcode/ | |||
| Sierra Wireless | AirLink | sconsole:12345 | 12345/tcp, 2332/tcp | 3G/4G gateway | telnet, ssh | official documentation | |
| Sierra Wireless | AirLink | user:12345, viewer:12345 | 9191/tcp | 3G/4G gateway | http | official documentation | |
| Sinapsi | eSolar | admin:admin | 80/tcp | Web-Server for photovoltaic applications | HTTP | http://www.sinapsitech.it/wp-content/uploads/2014/02/Handbook_standard_2.0_en.pdf | |
| SMA Solar Technology | Sunny WebBox | Installer:sma | 80/tcp | ICS device for data logging | HTTP | https://dariusfreamon.wordpress.com/2015/05/02/sunny-webbox-default-password-and-denial-of-service/ | |
| Stulz GmbH | Stulz WIB 8000 | Administrator, highest authorization: ganymed, Medium authorization: kallisto, Lowest authorization: europa | PLC | https://dariusfreamon.wordpress.com/2013/09/07/stulz-wib-8000-air-conditioning-web-interface-board-multiple-vulnerabilities/ | |||
| TAC AB | TAC Xenta 500/700/911/913, TAC Xenta 511, TAC Xenta 527, | root:root | PLC | http://www.xref.be/dpdf/tac_xenta911_xenta511_manuel_uk.pdf | |||
| Tecomat | Tecomat Foxtrot | 0:0 (role 0) , 1:1 (role 1), 2:2 (role 2), 3:3 (role 3), 4:4 (role 4), 5:5 (role 5), 6:6 (role 6), 7:7 (role 7), 8:8 (role 8), 9:9 (role 9) | PLC | http://dsec.ru/ipm-research-center/notification-of-vulnerabilities/tecomat_plc_paroli_po_umolchaniyu/ | |||
| Trafficware | ATMS.now | naztec:naztec | Advanced Traffic Management System | https://dariusfreamon.wordpress.com/2014/02/20/trafficware-atms-now-default-credentials/ | |||
| Tridium | NiagaraAX | tridium:niagara | Software for JACE-2, JACE-403 or JACE-545 | http://www.hvacc.net/pdf/tridium/docs_3.2.16/docJaceStartup/docJaceStartup.pdf | |||
| Turck | BL20-E-GW-EN, BL67-E-GW-EN | HTTP: password, FTP: (unspecified hardcoded) | 21/tcp, 80/tcp | PLC | http | http://pdb.turck.de/media/_in/Anlagen/D301173.pdf,http://ics-cert.us-cert.gov/advisories/ICSA-13-136-01 | |
| Ubiquiti | AirControl | ubnt:ubnt | 9005/tcp | Web Management Application | https://dariusfreamon.wordpress.com/2015/04/16/ubiquiti-aircontrol-web-management-default-admin-credentials/ | ||
| Ubiquiti | AirOS | ubnt:ubnt | 443/tcp | operation system | HTTPS | http://dl.ubnt.com/guides/airOS/airOS_UG.pdf | |
| Wago | WAGO-I/O-SYSTEM 750 | admin:wago, user:user, guest:guest | 80/tcp | Controller | http | http://www.wago.spb.ru/upload/information_system_28/3/2/8/item_328/information_items_property_340.pdf | |
| Wago | WAGO-I/O-IPC 758-870/000-xxx | http, ftp:, user:user00 , administrator:, su:ko2003wa | 80/tcp (http) | Compact Industrial PC | http, ftp | http://www.wago.com/wagoweb/documentation/758/eng_manu/870/q07580870_00000000_2en.pdf | |
| Wago | Modular I/O-System Linux Fieldbus Coupler 750-860 | root:wago , admin:wago, user:user , guest:guest | PLC | http://www.wago.com/wagoweb/documentation/750/eng_manu/coupler_controller/m07500860_00000000_0en.pdf | |||
| WashTec | SoftCare Evo Type SE10 | 00001 (limited access), 00000 (unlimited access) | Roll-over car wash system | http://www.washtec.com.au/files/tech-data/SoftCare2%20EVO%20Manual.pdf | |||
| Wellintech | KingSCADA 3.0 | administrator:administrator (role KVAdministrator) | Software | http://www.slideshare.net/DefconRussia/pavel-volobuev-alexander-minozhenko-alexander-polyakov-practical-demonstration-of-typical-attacks-and-0days-in-scada-and-plccontrollers | |||
| Westermo | TDW 33 | no password, just return, Hardcoded password: n3Y9kA6otYZu8, (?? TD-36) | Industrial Modem | http://www.etitudela.com/entrenadorcomunicaciones/downloads/modemrtbtdw33manual.pdf | |||
| Westermo | MRD-305-DIN/MRD-310/MRD-315/MRD-330/MRD-355/MRD-350/MRD-455 | admin:westermo | 80/tcp | Industrial router | http | http://www.eternity-sales.com/westermo/files/westermo_ug_6623-2266_mrd-305-DIN_en.pdf, Westermo MRD 330.pdf | |
| Westermo | RedFox Series, Wolverine Series, Lynx Series, Falcon Series, Viper Series | admin:westermo | 80/tcp | Industrial router | http | http://www.westermosales.com/pdfs/westermo_mg_6101-3201_weos.pdf | |
| Wonderware | Intouch | Administrator:Wonderware | SCADA | http://www.automation-talk.info/2011/01/default-intouch-login-username-password.html | |||
| Wonderware | Historian | SQL Server Login: aadbo:pwddbo, wwdbo:pwddbo, aaAdmin:pwAdmin, wwAdmin:wwAdmin, aaPower:pwPower, wwPower:wwPower, aaUser:pwUser, wwUser:wwUser | SQL Server | SSMS | https://drive.google.com/folderview?id=0B8or_Z9VHNfCeFIwbEY5RUk5SDA&usp=sharing | ||
| Wonderware | System Platform/Archestra | administrator:blank | Integrated Development Environment | https://insource.mindtouch.us/Support_Tickets/Industrial_Application_Server/Installation%2F%2FConfiguration/028076_-_What_is_the_default_Administrator_username_and_password_for_the_Archestra_IDE | |||
| Xzeres | 442SR | MyTurbine:m442+SRt | small wind turbine | https://dariusfreamon.wordpress.com/2015/05/03/xzeres-442s-wind-turbine-web-interface-default-credentials/ | |||
| Yokogawa | YFGW410 gateway | admin:!admin | Wireless Management Station | http://www.yokogawa.com/us/support/knowledgebase/i-cannot-login-to-the-yfgw410-gateway-what-is-the-default-username-and-password-of-a-yfgw410-isa100-gateway.htm | |||
| Yokogawa | DX1000/DX1000N/DX2000 Advanced | Administrator 1:Admin1, Administrator 2:Admin2, ..., Administrator 5:Admin5, User 1:User01, ..., User 90:User90 | Software | http://web-material3.yokogawa.com/IM04L41B01-05EN_020.pdf | |||
| Yokogawa | CENTUM CS 3000 DCS | CENTUM:CENTUM | Distributed Control System | http://www.allinterview.com/showanswers/170266/having-yokogawa-centum-cs-3000-dcs-2-fcs-4-operation-download-message-appears-eq.html | |||
| Yokogawa | EJX910A Multivariable Transmitter HART Communication Type | YOKOGAWA. (to release the Write Protect mode), | Multivariable transmitter | http://www.controlswarehouse.com/sheets/meriam/EJX910HARTIM01C25R02-01E_001.pdf | |||
| Yokogawa | WT 3000 Driver | anonymous:blank (Ethernet access) | Precision Power Analyzer | http://www.electro-meters.com/Assets/pdf2_files/Yokogawa/Power_meters/WT3000_pdfs/WT3000%20Communication.pdf | |||
| Zoe Medical | Nightingale PPM3 | Set Dial 1 to 49, Set Dial 2 to 48, Set Dial 3 to 46 | Vital Sign Monitor With CO2 | https://dariusfreamon.wordpress.com/2015/07/11/zoe-medical-nightingale-ppm3-default-passcode/ |