VYPR

CWE-321

Use of Hard-coded Cryptographic Key

VariantDraftLikelihood: High

Description

The product uses a hard-coded, unchangeable cryptographic key.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (327)

page 16 of 17
  • CVE-2026-4477LowMar 20, 2026
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was determined in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This affects an unknown function of the component WPA/WPS. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack can only be done within the local network.…

  • CVE-2025-10080LowSep 8, 2025
    risk 0.20cvss 3.1epss 0.00

    A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue is the function getTokensecret of the file datart/security/src/main/java/datart/security/util/AESUtil.java of the component API. The manipulation leads to use of hard-coded…

  • CVE-2024-10920LowNov 6, 2024
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this issue is the function doFilterInternal of the file travels-java-api-master\src\main\java\io\github\mariazevedo88\travelsjavaapi\filters\JwtAuthenticationTokenFi…

  • CVE-2024-1258LowFeb 6, 2024
    risk 0.20cvss 3.1epss 0.01

    A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file api/config/params.php of the component API. The manipulation of the argument JWT_KEY_ADMIN leads to use of…

  • CVE-2026-5420LowApr 2, 2026
    risk 0.16cvss 2.5epss 0.00

    A security flaw has been discovered in Shinrays Games Goods Triple App up to 1.200. The affected element is an unknown function of the file jRwTX.java of the component cats.goods.sort.sorting.games. Performing a manipulation of the argument AES_IV/AES_PASSWORD results in use of…

  • CVE-2026-5310LowApr 1, 2026
    risk 0.16cvss 2.5epss 0.00

    A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the file IperiusAccounts.ini. Such manipulation leads to use of hard-coded cryptographic key . The attack must be carried out locally. This attack is characterized…

  • CVE-2026-44278LowMay 12, 2026
    risk 0.15cvss 2.3epss 0.00

    A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via

  • CVE-2025-6666LowNov 29, 2025
    risk 0.13cvss 2.0epss 0.00

    A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an unknown functionality of the component NFC Handler. Executing manipulation can lead to use of hard-coded cryptographic key . The physical device can be…

  • CVE-2011-5064Jan 14, 2012
    risk 0.01cvss epss 0.07

    DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass…

  • CVE-2026-14804CriAug 4, 2026
    risk 0.00cvss 9.1epss 0.00

    Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

  • CVE-2026-18754CriAug 4, 2026
    risk 0.00cvss 9.1epss 0.00

    The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and…

  • CVE-2026-18753CriAug 4, 2026
    risk 0.00cvss 9.1epss 0.00

    The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and…

  • CVE-2026-16504CriJul 31, 2026
    risk 0.00cvss 9.8epss 0.00

    Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

  • CVE-2026-54363CriJul 30, 2026
    risk 0.00cvss 9.1epss 0.00

    CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket.Decrypt() across all…

  • CVE-2021-32086CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a…

  • CVE-2026-56271CriJul 12, 2026
    risk 0.00cvss 9.8epss 0.00

    Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware…

  • CVE-2026-57172HigJul 7, 2026
    risk 0.00cvss epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded default share link signature key, allowing an attacker who can obtain a passwordless share for a resource and user to use the known key link-pwd-fit2cloud to…

  • CVE-2026-39031MedJun 26, 2026
    risk 0.00cvss 5.5epss 0.00

    Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded 142-byte static key array to encrypt credentials. An 8-character prefix is stored in cleartext alongside the ciphertext. This allows an attacker with local access to recover any encrypted password to…

  • CVE-2026-54833HigJun 26, 2026
    risk 0.00cvss 7.4epss 0.00

    Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.

  • CVE-2026-9220HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initialization vectors. This allows an attacker to decrypt Setracker2 watch traffic.