VYPR

CWE-259

Use of Hard-coded Password

VariantDraftLikelihood: High

Description

The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (195)

page 10 of 10
  • CVE-2025-9091LowAug 17, 2025
    risk 0.16cvss 2.5epss 0.00

    A security flaw has been discovered in Tenda AC20 16.03.08.12. Affected by this vulnerability is an unknown functionality of the file /etc_ro/shadow. The manipulation leads to hard-coded credentials. It is possible to launch the attack on the local host. The complexity of an…

  • CVE-2025-36609LowJul 30, 2025
    risk 0.16cvss 2.5epss 0.00

    Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2025-1879LowMar 3, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This issue affects some unknown processing of the component APK. The manipulation leads to hard-coded credentials. It is possible to launch the attack on the physical device. It was…

  • CVE-2024-7155LowJul 28, 2024
    risk 0.16cvss 2.5epss 0.00

    A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. It is possible to launch the…

  • CVE-2020-12039LowJun 29, 2020
    risk 0.16cvss 2.4epss 0.00

    Baxter Sigma Spectrum Infusion Pumps Sigma Spectrum Infusion System v's6.x model 35700BAX & Baxter Spectrum Infusion System v's8.x model 35700BAX2 contain hardcoded passwords when physically entered on the keypad provide access to biomedical menus including device settings, view…

  • CVE-2025-7741LowMar 30, 2026
    risk 0.14cvss epss 0.00

    Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user account (PROG) used for CENTUM Authentication Mode within the system. Under the following conditions, there is a risk that an attacker could log in as the…

  • CVE-2025-47823LowJun 27, 2025
    risk 0.14cvss 2.2epss 0.00

    Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system.

  • CVE-2025-47821LowJun 27, 2025
    risk 0.14cvss 2.2epss 0.00

    Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system.

  • CVE-2025-47818LowJun 27, 2025
    risk 0.14cvss 2.2epss 0.00

    Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection.

  • CVE-2026-20316MedKEVJul 29, 2026
    risk 0.12cvss 5.3epss 0.01

    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This…

  • CVE-2025-9806LowSep 2, 2025
    risk 0.12cvss 1.9epss 0.00

    A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed…

  • CVE-2025-9778LowSep 1, 2025
    risk 0.12cvss 1.9epss 0.00

    A security vulnerability has been detected in Tenda W12 up to 3.0.0.6(3948). Affected is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. The manipulation leads to hard-coded credentials. An attack has to be approached locally. The…

  • CVE-2012-5862Nov 23, 2012
    risk 0.04cvss epss 0.12

    These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in the device, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access.

  • CVE-2014-5405Apr 3, 2015
    risk 0.00cvss epss 0.02

    Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.

  • CVE-2014-2363Jul 26, 2014
    risk 0.00cvss epss 0.02

    Morpho Itemiser 3 8.17 has hardcoded administrative credentials, which makes it easier for remote attackers to obtain access via a login request.