VYPR

CWE-259

Use of Hard-coded Password

VariantDraftLikelihood: High

Description

The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (195)

page 1 of 10
  • CVE-2025-8730CriAug 8, 2025
    risk 0.67cvss 9.8epss 0.03

    A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functionality of the component Web Interface. The manipulation leads to hard-coded credentials. The attack may be launched remotely. The…

  • CVE-2024-7332CriAug 1, 2024
    risk 0.65cvss 9.8epss 0.21

    A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of hard-coded password. It is possible to…

  • CVE-2024-32741CriMay 14, 2024
    risk 0.65cvss 10.0epss 0.01

    A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by default . An attacker who manages to crack the password hash gains…

  • CVE-2022-45444CriJan 18, 2023
    risk 0.65cvss 10.0epss 0.01

    Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select users in the application’s database. This could allow a remote attacker to login to the database with unrestricted access.

  • CVE-2026-35905CriJun 4, 2026
    risk 0.64cvss 9.8epss 0.00

    T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account.

  • CVE-2026-7251CriMay 26, 2026
    risk 0.64cvss 9.8epss 0.01

    Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the…

  • CVE-2025-59388CriMar 12, 2026
    risk 0.64cvss 9.8epss 0.00

    A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: Hyper Data Protector 2.3.1.455 and…

  • CVE-2025-70041CriMar 11, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master.

  • CVE-2026-25753CriFeb 6, 2026
    risk 0.64cvss 9.8epss 0.00

    PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass account takeover, allowing any attacker to log in as any…

  • CVE-2025-15111CriDec 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploit the weak default administrative credentials to obtain full control of the home automation system.

  • CVE-2025-11126CriSep 29, 2025
    risk 0.64cvss 9.8epss 0.01

    A security flaw has been discovered in Apeman ID71 218.53.203.117. This vulnerability affects unknown code of the file /system/www/system.ini. The manipulation results in hard-coded credentials. The attack may be performed from remote. The exploit has been released to the public…

  • CVE-2025-20286CriJun 4, 2025
    risk 0.64cvss 9.9epss 0.01

    A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations,…

  • CVE-2025-30115CriMar 18, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Default Credentials Cannot Be Changed. It uses a fixed default SSID and password ("qwertyuiop"), which cannot be modified by users. The SSID is continuously broadcast, allowing unauthorized access to the…

  • CVE-2025-27638CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Hardcoded Password V-2024-013.

  • CVE-2025-1100CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to execute arbitrary code with root privileges via SSH.

  • CVE-2024-4996CriDec 18, 2024
    risk 0.64cvss 9.8epss 0.01

    Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Wapro ERP installations. This issue affects Wapro ERP Desktop…

  • CVE-2024-25825CriOct 9, 2024
    risk 0.64cvss 9.8epss 0.01

    FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password.

  • CVE-2024-43423CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.

  • CVE-2023-37231CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.

  • CVE-2024-42639CriAug 16, 2024
    risk 0.64cvss 9.8epss 0.01

    H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as root.