VYPR

CWE-321

Use of Hard-coded Cryptographic Key

VariantDraftLikelihood: High

Description

The product uses a hard-coded, unchangeable cryptographic key.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (361)

page 14 of 19
  • CVE-2026-84483MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens using the public site URL and current time. Attackers can forge authentication tokens by computing…

  • CVE-2026-17468MedAug 13, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use of a hardcoded cryptographic key.

  • CVE-2026-49006MedAug 7, 2026
    risk 0.34cvss 5.3epss 0.00

    By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission.

  • CVE-2026-9770MedJul 15, 2026
    risk 0.34cvss 5.3epss 0.00

    Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices.  An attacker with access to the firmware image can extract the embedded key.  Successful exploitation may allow an…

  • CVE-2026-50226MedJun 4, 2026
    risk 0.34cvss 5.3epss 0.00

    Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.

  • CVE-2026-8739MedMay 17, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigComponent.java. The manipulation of the argument privatefile_key results in use…

  • CVE-2026-8243MedMay 10, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This affects an unknown function of the component JNLP Deployment Endpoint. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be performed from remote.…

  • CVE-2026-5549MedApr 5, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some unknown functionality of the file /webroot_ro/pem/privkeySrv.pem of the component RSA 2048-bit Private Key Handler. Executing a manipulation can lead to use of hard-coded…

  • CVE-2026-5527MedApr 5, 2026
    risk 0.34cvss 5.3epss 0.00

    A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Private Key Handler. This manipulation causes use of hard-coded cryptographic key …

  • CVE-2025-12177MedNov 8, 2025
    risk 0.34cvss 5.3epss 0.00

    The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to…

  • CVE-2025-35052MedOct 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values can specify paths to download files, potentially bypassing authentication and authorization, for example, the 'qs' parameter used in…

  • CVE-2025-58069MedSep 23, 2025
    risk 0.34cvss 5.3epss 0.00

    The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software contains a hard-coded AES key used to protect the initial messages of a new KOPS session.

  • CVE-2025-6071MedJul 3, 2025
    risk 0.34cvss 5.3epss 0.00

    Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. An attacker can gain access to salted information to decrypt MQTT information. This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through…

  • CVE-2024-46889MedNov 12, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application uses hard-coded cryptographic key material to obfuscate configuration files. This could allow an attacker to learn that cryptographic key material through reverse…

  • CVE-2023-6482MedJan 27, 2024
    risk 0.34cvss 5.2epss 0.00

    Use of encryption key derived from static information in Synaptics Fingerprint Driver allows an attacker to set up a TLS session with the fingerprint sensor and send restricted commands to the fingerprint sensor. This may allow an attacker, who has physical access to the…

  • CVE-2023-21404MedMay 8, 2023
    risk 0.34cvss 5.3epss 0.00

    AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or any customer data.

  • CVE-2026-24166MedAug 25, 2026
    risk 0.33cvss 5.1epss 0.00

    NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful exploit of this vulnerability might lead to information disclosure and escalation of privileges.

  • CVE-2026-11505MedJun 8, 2026
    risk 0.33cvss 5.0epss 0.00

    A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be launched remotely.…

  • CVE-2025-12615MedNov 3, 2025
    risk 0.33cvss 5.0epss 0.00

    A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . The attack may be performed from…

  • CVE-2025-56802MedOct 21, 2025
    risk 0.33cvss 5.1epss 0.00

    The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files allowing attackers with local access to decrypt sensitive application data stored in %APPDATA%. A different vulnerability than CVE-2025-56801. NOTE: the…