VYPR

CWE-321

Use of Hard-coded Cryptographic Key

VariantDraftLikelihood: High

Description

The product uses a hard-coded, unchangeable cryptographic key.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (327)

page 12 of 17
  • CVE-2024-1920MedFeb 27, 2024
    risk 0.36cvss 5.6epss 0.01

    A vulnerability, which was classified as critical, has been found in osuuu LightPicture up to 1.2.2. This issue affects the function handle of the file /app/middleware/TokenVerify.php. The manipulation leads to use of hard-coded cryptographic key . The attack may be initiated…

  • CVE-2022-34386MedFeb 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.

  • CVE-2021-27481MedJun 16, 2021
    risk 0.36cvss 5.5epss 0.00

    ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcoded. This could allow an attacker to gain access to sensitive information.

  • CVE-2020-25233MedDec 14, 2020
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The firmware update of affected devices contains the private RSA key that is used as a basis for encryption of communication with the device.

  • CVE-2020-25231MedDec 14, 2020
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3), LOGO! Soft Comfort (All versions < V8.3). The encryption of program data for the affected devices uses a static key. An attacker could use this key to extract confidential…

  • CVE-2025-66454MedDec 2, 2025
    risk 0.35cvss 6.5epss 0.00

    Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a hardcoded default worker secret ("dev") that is never validated or overridden during normal server startup. As a result, any unauthenticated attacker who knows…

  • CVE-2025-54471MedOct 30, 2025
    risk 0.35cvss 6.5epss 0.00

    NeuVector used a hard-coded cryptographic key embedded in the source code. At compilation time, the key value was replaced with the secret key value and used to encrypt sensitive configurations when NeuVector stores the data.

  • CVE-2024-45837MedNov 22, 2024
    risk 0.35cvss 5.4epss 0.00

    Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A network-adjacent unauthenticated attacker may log in to SFTP service and obtain and/or manipulate unauthorized files.

  • CVE-2020-25193MedMar 18, 2022
    risk 0.35cvss 5.3epss 0.01

    By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06, attackers would be able to intercept and decrypt encrypted traffic through an HTTPS connection.

  • CVE-2020-25180MedMar 18, 2022
    risk 0.35cvss 5.3epss 0.01

    Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny…

  • CVE-2026-49006MedAug 7, 2026
    risk 0.34cvss 5.3epss 0.00

    By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission.

  • CVE-2026-9770MedJul 15, 2026
    risk 0.34cvss 5.3epss 0.00

    Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices.  An attacker with access to the firmware image can extract the embedded key.  Successful exploitation may allow an…

  • CVE-2026-50226MedJun 4, 2026
    risk 0.34cvss 5.3epss 0.00

    Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.

  • CVE-2026-8739MedMay 17, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigComponent.java. The manipulation of the argument privatefile_key results in use…

  • CVE-2026-8243MedMay 10, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This affects an unknown function of the component JNLP Deployment Endpoint. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be performed from remote.…

  • CVE-2026-5549MedApr 5, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some unknown functionality of the file /webroot_ro/pem/privkeySrv.pem of the component RSA 2048-bit Private Key Handler. Executing a manipulation can lead to use of hard-coded…

  • CVE-2026-5527MedApr 5, 2026
    risk 0.34cvss 5.3epss 0.00

    A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Private Key Handler. This manipulation causes use of hard-coded cryptographic key …

  • CVE-2025-12177MedNov 8, 2025
    risk 0.34cvss 5.3epss 0.00

    The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to…

  • CVE-2025-35052MedOct 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values can specify paths to download files, potentially bypassing authentication and authorization, for example, the 'qs' parameter used in…

  • CVE-2025-58069MedSep 23, 2025
    risk 0.34cvss 5.3epss 0.00

    The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software contains a hard-coded AES key used to protect the initial messages of a new KOPS session.