VYPR

CWE-259

Use of Hard-coded Password

VariantDraftLikelihood: High

Description

The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (209)

page 11 of 11
  • CVE-2025-7741LowMar 30, 2026
    risk 0.14cvss —epss 0.00

    Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user account (PROG) used for CENTUM Authentication Mode within the system. Under the following conditions, there is a risk that an attacker could log in as the…

  • CVE-2025-47823LowJun 27, 2025
    risk 0.14cvss 2.2epss 0.00

    Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system.

  • CVE-2025-47821LowJun 27, 2025
    risk 0.14cvss 2.2epss 0.00

    Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system.

  • CVE-2025-47818LowJun 27, 2025
    risk 0.14cvss 2.2epss 0.00

    Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection.

  • CVE-2025-9806LowSep 2, 2025
    risk 0.12cvss 1.9epss 0.00

    A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed…

  • CVE-2025-9778LowSep 1, 2025
    risk 0.12cvss 1.9epss 0.00

    A security vulnerability has been detected in Tenda W12 up to 3.0.0.6(3948). Affected is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. The manipulation leads to hard-coded credentials. An attack has to be approached locally. The…

  • CVE-2012-5862Nov 23, 2012
    risk 0.04cvss —epss 0.12

    These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in the device, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access.

  • CVE-2014-5405Apr 3, 2015
    risk 0.00cvss —epss 0.02

    Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.

  • CVE-2014-2363Jul 26, 2014
    risk 0.00cvss —epss 0.02

    Morpho Itemiser 3 8.17 has hardcoded administrative credentials, which makes it easier for remote attackers to obtain access via a login request.