VYPR

CWE-321

Use of Hard-coded Cryptographic Key

VariantDraftLikelihood: High

Description

The product uses a hard-coded, unchangeable cryptographic key.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (361)

page 18 of 19
  • CVE-2024-1258LowFeb 6, 2024
    risk 0.20cvss 3.1epss 0.01

    A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file api/config/params.php of the component API. The manipulation of the argument JWT_KEY_ADMIN leads to use of…

  • CVE-2026-5420LowApr 2, 2026
    risk 0.16cvss 2.5epss 0.00

    A security flaw has been discovered in Shinrays Games Goods Triple App up to 1.200. The affected element is an unknown function of the file jRwTX.java of the component cats.goods.sort.sorting.games. Performing a manipulation of the argument AES_IV/AES_PASSWORD results in use of…

  • CVE-2026-5310LowApr 1, 2026
    risk 0.16cvss 2.5epss 0.00

    A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the file IperiusAccounts.ini. Such manipulation leads to use of hard-coded cryptographic key . The attack must be carried out locally. This attack is characterized…

  • CVE-2026-44278LowMay 12, 2026
    risk 0.15cvss 2.3epss 0.00

    A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via

  • CVE-2025-6666LowNov 29, 2025
    risk 0.13cvss 2.0epss 0.00

    A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an unknown functionality of the component NFC Handler. Executing a manipulation can lead to use of hard-coded cryptographic key . The physical device can be…

  • CVE-2026-50606LowSep 17, 2026
    risk 0.08cvss —epss 0.00

    A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use…

  • CVE-2011-5064Jan 14, 2012
    risk 0.01cvss —epss 0.06

    DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass…

  • CVE-2026-54363CriJul 30, 2026
    risk 0.00cvss 9.1epss 0.00

    CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket.Decrypt() across all…

  • CVE-2021-32086CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a…

  • CVE-2026-56271CriJul 12, 2026
    risk 0.00cvss 9.8epss 0.01

    Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware…

  • CVE-2026-57172HigJul 7, 2026
    risk 0.00cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded default share link signature key, allowing an attacker who can obtain a passwordless share for a resource and user to use the known key link-pwd-fit2cloud to…

  • CVE-2026-39031MedJun 26, 2026
    risk 0.00cvss 5.5epss 0.00

    Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded 142-byte static key array to encrypt credentials. An 8-character prefix is stored in cleartext alongside the ciphertext. This allows an attacker with local access to recover any encrypted password to…

  • CVE-2026-54833HigJun 26, 2026
    risk 0.00cvss 7.4epss 0.00

    Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.

  • CVE-2026-9220HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initialization vectors. This allows an attacker to decrypt Setracker2 watch traffic.

  • CVE-2026-35019HigJun 23, 2026
    risk 0.00cvss 8.1epss 0.01

    NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by exploiting a hardcoded AES-256 key used to encrypt session cookies for the web management interface.…

  • CVE-2026-9642May 26, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-58134HigMay 3, 2025
    risk 0.00cvss 8.1epss 0.01

    Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC session cookie secret by default. These predictable default secrets can be exploited by an attacker to forge session cookies.  An attacker who knows or guesses the…

  • CVE-2023-27583CriMar 13, 2023
    risk 0.00cvss 9.8epss 0.01

    PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the hard-coded JWT key to sign JWT token and perform any actions as a user with admin privileges. Version 3.1.3 has a patch for the…

  • CVE-2022-29186CriMay 20, 2022
    risk 0.00cvss 9.1epss 0.01

    Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and rundeck-enterprise docker images contained a pre-generated SSH keypair. If the id_rsa.pub public key of the keypair was copied to authorized_keys files on…

  • CVE-2014-5403Apr 3, 2015
    risk 0.00cvss —epss 0.02

    Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to obtain sensitive information by sniffing the network.