OpenJS Foundation (IBM) Node-RED Flow-Based Programming Tool — Default Password
Default username and password for the OpenJS Foundation (IBM) Node-RED Flow-Based Programming Tool: (blank) / (blank). Learn how to log in and how to change the default credentials.
Node-RED is a widely-deployed flow-based programming tool for IoT and automation, originally developed by IBM and now hosted by the OpenJS Foundation. By default, Node-RED runs with NO authentication whatsoever — the editor and all admin APIs are fully open to anyone with network access on port 1880. Authentication must be explicitly configured in settings.js using bcrypt-hashed passwords. The Node-RED documentation explicitly warns that 'by default, the editor is not secured — anyone who can access its IP address can access the editor and deploy changes.' This is a well-known and frequently exploited security gap on exposed installations.
| Nom d’utilisateur | Mot de passe | Accès | Version / firmware | Notes |
|---|---|---|---|---|
(vide / aucun) | (vide / aucun) | Web UI | All versions (authentication off by default) | Node-RED editor at http://<host>:1880/ is fully open with no login required. Admin API also unauthenticated. Requires manual configuration in settings.js to enable auth. |
Utilisation responsable
Cette base de données répertorie les identifiants par défaut documentés publiquement afin que les administrateurs puissent les trouver et les changer. Utilisez-les uniquement sur des systèmes que vous possédez ou que vous êtes autorisé à tester.
Appareils associés
admin/pfsenseWeb UIadmin/adminWeb UIadmin/∅Web UIadmin/adminWeb UIadmin/adminWeb UIadmin/radiusWeb UI