Right now, could you name every device on your network and confirm none of them still uses the password it shipped with? That gap is where default passwords live, and it's why they remain one of the most dependable ways into a network.
What is a default password?
A default password is the login a device or service ships with from the factory. It exists so the device can be set up, and it's meant to be changed immediately afterward. Often it isn't. And these credentials aren't secret. They're published in vendor manuals, listed on public sites, and built into every cybercriminal's toolkit.
So, if everyone knows admin/admin is bad, why does it keep turning up?
- The device is forgotten. A switch installed six years ago, a camera in a stairwell, equipment a contractor set up. You can't rotate a credential on a device you don't remember owning.
- It's too important to touch. A system that can't take downtime, or equipment where changing the login risks breaking an integration no one fully understands. The default survives because touching it feels riskier than leaving it.
- It can't be changed at all. This is the worst case: credentials hardcoded into the device firmware by the manufacturer, with no interface to change them. It's more common than it sounds, and not just on cheap hardware. You can find hardcoded logins in medical devices, and even certified industrial equipment.
Regulators are closing in on that last case. The EU Cyber Resilience Act (Regulation 2024/2847) requires manufacturers to eliminate default passwords, so new devices ship with unique credentials or force a change at first use. The obligations apply from December 2027, but they only cover new products. The installed base already on your network is still yours to find.
Where default passwords actually hide
Most teams have locked down the obvious systems: servers, the main firewall, the accounts people use daily. Default passwords don't survive there. They survive on the equipment at the edges, and the risk climbs the further you get from what you watch:
- Network gear you set and forgot. Routers, switches, and wireless controllers configured once and untouched since. They work, so no one logs in, so no one notices the login never changed.
- Server management controllers you forgot were reachable. Most servers carry a second way in: a small built-in system that controls the machine remotely, even when it's powered off. Dell's iDRAC historically shipped with root/calvin; IBM's with USERID/PASSW0RD. Whoever reaches one owns the server, and they sit quietly in the background where no one looks.
- Everyday hardware no one thinks of as a computer. IP cameras, power supplies that still answer to apc/apc, badge readers, storage appliances, printers. Each is a networked computer with a login it never lost.
- Operational technology, the deepest blind spot. In manufacturing, utilities, and energy, physical processes run on PLCs, remote terminal units, and the SCADA systems above them. Defaults are more common here than anywhere, for the worst reasons: installed by an integrator years ago, expected to run for a decade untouched, and often impossible to change without specialist work.
Why default credentials are more dangerous in OT and SCADA environments
The stakes are higher in operational technology. On an office system, a stolen login usually means stolen data. On an industrial system, it can mean physical disruption to a production line, a power grid, or a water supply.
This is not hypothetical. In November 2023, attackers took control of equipment at the Municipal Water Authority of Aliquippa in Pennsylvania by reaching a programmable logic controller that was exposed to the internet with its default password still in place. CISA's guidance to other utilities named the exact credential to remove: the default password "1111." The same model of controller is used across manufacturing, pipelines, and chemical plants, so the exposure was never limited to one sector. The water authority had to fall back to manual operations while it recovered.
That is why default credentials sit at the center of credential-based attacks on critical infrastructure, and why OT security demands more scrutiny of them than IT does. It is also why NIS2 puts weight on securing these environments.
Finding them: manual review versus the assessment you already run
Checking for default credentials is not hard in principle, and free tools exist to help. But they give you a point-in-time snapshot of a moving target. You run the check, you get a list, and the next week someone racks a new appliance or a contractor connects a device, and the list is stale. Keeping it current across hundreds of devices from dozens of vendors is a job no one owns, and the forgotten devices, the ones most likely to still run a default, are the ones a one-off sweep misses.
The reliable method is to make the check part of the assessment you already run. A vulnerability management platform that scans your network to inventory what is connected already knows what each device is. That inventory is exactly what a default credential check needs, and it runs on every assessment rather than the one afternoon someone remembered to look.
How Holm Security checks for default passwords
Holm Security runs over 300 default password checks as part of standard network assessment. There's no separate tool and no extra scan. If you're assessing your network, the checks run.

How the check runs matters here. Rather than brute forcing, throwing a large password list at every device, each check identifies the device first, then tries only a small set of known factory credentials for that specific product. A Dell iDRAC is checked against root and calvin, a Microsoft SQL Server against its blank sa account, a PostgreSQL instance against postgres/postgres, an APC power supply against apc/apc. The credentials come from a maintained library of documented factory logins spanning roughly 130 vendors, matched to what the platform detects.
- Each device sees only its own handful of known defaults, so the risk of lockouts stays low.
- The checks build on the asset discovery the platform already does, so they reach the forgotten edge devices a manual review never gets to.
- Coverage concentrates on high-consequence gear, network equipment, server controllers, appliances, and databases, so findings point at the systems that matter.
For operational technology, the same method applies with extra caution. Industrial equipment can be fragile, so scan scope and profile stay in your control.
Find your default credentials before someone else does. See how Holm Security surfaces default passwords across your network, safely and as part of the assessment you already run. Speak with an expert today!
FAQ
What is a default password?
A default password is the credential a device or service ships with from the factory, meant to be changed during setup. Common examples include admin/admin and blank administrator accounts. When left unchanged, they give anyone with the manual a way in.
Why are default passwords a security risk?
Default credentials are public knowledge and appear in attacker toolkits, so an unchanged default is effectively an open door. The risk is highest on forgotten or hard-to-reach devices, and most severe in operational technology, where access can cause physical disruption.
How do I find default passwords across my network?
Manual checking works for a few known devices but doesn't scale. The reliable approach is a vulnerability management platform that inventories every connected device and checks each one against its known factory credentials automatically.
Are default password checks safe to run on fragile or OT equipment?
When done correctly, yes. A safe check tries only the few credentials a detected device is known to ship with, not a long password list, which keeps attempts minimal. On sensitive operational technology, you should still control the scan scope and profile.
Holm Security
Holm Security's Next-Gen Vulnerability Management Platform delivers unparalleled 360-degree coverage and comprehensive insights to enable you to detect vulnerabilities, assess risk, and prioritize remediation for every asset across your entire organization.



