Weak Passwords
📖 Introduction
Weak Passwords scans for extensions with insecure SIP passwords. Identifies potential security vulnerabilities before attackers do.
---
⚠️ Security Critical
CAUTION
Address all weak passwords: They are the #1 cause of toll fraud.---
🖥️ Accessing the Module
Navigation:PBX → Tools → Weak Passwords

---
📊 Scan Results

| Column | Description | |
|---|---|---|
| Extension | Extension number | |
| Name | User name | |
| Issue | Type of weakness | |
| Severity | High/Medium/Low | |
| Action | Fix button |
Weakness Types
| Type | Risk Level | |
|---|---|---|
| Same as extension | 🔴 Critical | |
| Common password | 🔴 Critical | |
| Too short (<8) | 🟠 High | |
| No numbers | 🟡 Medium | |
| Dictionary word | 🟡 Medium |
🚀 Fixing Weak Passwords
Individual Fix
- Click Fix next to extension
- New password auto-generated
- Update phone with new password
Bulk Fix
- Select all weak passwords
- Click Generate New Passwords
- Download CSV with new passwords
- Update all phones
---
💡 Tips
TIP
Run weekly: Schedule regular security scans.TIP
Force strong passwords: Enable in Security Settings.TIP
Auto-generate: Let system create secure passwords.CAUTION
Never use extension as password: Most common attack vector.---
🔗 Related Modules
- Security Settings — Password policies
- Extensions — Update passwords