CWE-259
Use of Hard-coded Password
Description
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (209)
page 11 of 11| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-7741 | Low | 0.14 | — | 0.00 | Mar 30, 2026 | Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user account (PROG) used for CENTUM Authentication Mode within the system. Under the following conditions, there is a risk that an attacker could log in as the… | ||
| CVE-2025-47823 | Low | 0.14 | 2.2 | 0.00 | Jun 27, 2025 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system. | ||
| CVE-2025-47821 | Low | 0.14 | 2.2 | 0.00 | Jun 27, 2025 | Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system. | ||
| CVE-2025-47818 | Low | 0.14 | 2.2 | 0.00 | Jun 27, 2025 | Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection. | ||
| CVE-2025-9806 | Low | 0.12 | 1.9 | 0.00 | Sep 2, 2025 | A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed… | ||
| CVE-2025-9778 | Low | 0.12 | 1.9 | 0.00 | Sep 1, 2025 | A security vulnerability has been detected in Tenda W12 up to 3.0.0.6(3948). Affected is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. The manipulation leads to hard-coded credentials. An attack has to be approached locally. The… | ||
| CVE-2012-5862 | 0.04 | — | 0.12 | Nov 23, 2012 | These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in the device, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access. | |||
| CVE-2014-5405 | 0.00 | — | 0.02 | Apr 3, 2015 | Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password. | |||
| CVE-2014-2363 | 0.00 | — | 0.02 | Jul 26, 2014 | Morpho Itemiser 3 8.17 has hardcoded administrative credentials, which makes it easier for remote attackers to obtain access via a login request. |
- risk 0.14cvss —epss 0.00
Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user account (PROG) used for CENTUM Authentication Mode within the system. Under the following conditions, there is a risk that an attacker could log in as the…
- risk 0.14cvss 2.2epss 0.00
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system.
- risk 0.14cvss 2.2epss 0.00
Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system.
- risk 0.14cvss 2.2epss 0.00
Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection.
- risk 0.12cvss 1.9epss 0.00
A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed…
- risk 0.12cvss 1.9epss 0.00
A security vulnerability has been detected in Tenda W12 up to 3.0.0.6(3948). Affected is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. The manipulation leads to hard-coded credentials. An attack has to be approached locally. The…
- CVE-2012-5862Nov 23, 2012risk 0.04cvss —epss 0.12
These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in the device, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access.
- CVE-2014-5405Apr 3, 2015risk 0.00cvss —epss 0.02
Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.
- CVE-2014-2363Jul 26, 2014risk 0.00cvss —epss 0.02
Morpho Itemiser 3 8.17 has hardcoded administrative credentials, which makes it easier for remote attackers to obtain access via a login request.