VYPR

CWE-259

Use of Hard-coded Password

VariantDraftLikelihood: High

Description

The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (195)

page 2 of 10
  • CVE-2024-41616CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.

  • CVE-2024-36526CriJul 9, 2024
    risk 0.64cvss 9.8epss 0.01

    ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.

  • CVE-2023-46685CriJul 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution.

  • CVE-2024-4708CriJul 2, 2024
    risk 0.64cvss 9.8epss 0.01

    mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.

  • CVE-2024-38902CriJun 24, 2024
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R230 V100R002 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

  • CVE-2024-3700CriJun 10, 2024
    risk 0.64cvss 9.8epss 0.00

    Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations. This issue affects Estomed Sp. z o.o. Simple Care software in all versions. The…

  • CVE-2024-3699CriJun 10, 2024
    risk 0.64cvss 9.8epss 0.00

    Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all drEryk Gabinet installations.This issue affects drEryk Gabinet software versions from 7.0.0.0 through 9.17.0.0.

  • CVE-2024-1228CriJun 10, 2024
    risk 0.64cvss 9.8epss 0.00

    Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations. This issue affects Eurosoft Przychodnia software before version 20240417.001 (from…

  • CVE-2024-2420CriMay 30, 2024
    risk 0.64cvss 9.8epss 0.01

    LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker to bypass authentication requirements.

  • CVE-2024-34025CriMay 15, 2024
    risk 0.64cvss 9.8epss 0.01

    CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing authentication and gaining administrator privileges.

  • CVE-2024-33625CriMay 15, 2024
    risk 0.64cvss 9.8epss 0.01

    CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication.

  • CVE-2024-31810CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2024-27488CriApr 8, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate…

  • CVE-2024-28010CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Use of Hard-coded Password in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP,…

  • CVE-2023-2645CriMay 11, 2023
    risk 0.64cvss 9.8epss 0.03

    A vulnerability, which was classified as critical, was found in USR USR-G806 1.0.41. Affected is an unknown function of the component Web Management Page. The manipulation of the argument username/password with the input root leads to use of hard-coded password. It is possible…

  • CVE-2022-41653CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user login credentials and control the system.

  • CVE-2022-22144CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. During system startup this functionality is always called, leading to a known root password. An attacker does not have to do…

  • CVE-2022-30271CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.

  • CVE-2017-20039CriJun 11, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been classified as very critical. This affects an unknown part. The manipulation leads to weak authentication. It is possible to initiate the attack remotely.

  • CVE-2021-34601CriApr 27, 2022
    risk 0.64cvss 9.8epss 0.01

    In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below is prone to hardcoded ssh credentials. An attacker may use the password to gain administrative access to the web-UI.