VYPR

CWE-321

Use of Hard-coded Cryptographic Key

VariantDraftLikelihood: High

Description

The product uses a hard-coded, unchangeable cryptographic key.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (327)

page 4 of 17
  • CVE-2026-45433HigJun 4, 2026
    risk 0.57cvss epss 0.00

    This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerability by extracting the cryptographic private key from the firmware, which could lead to decryption of…

  • CVE-2026-42518HigApr 29, 2026
    risk 0.57cvss epss 0.00

    This vulnerability exists in e-Sushrut due to disclosure of sensitive information and hardcoded AES encryption keys in client-side JavaScript. An unauthenticated remote attacker could exploit this vulnerability by accessing the client-side code to extract sensitive information…

  • CVE-2026-25894CriFeb 9, 2026
    risk 0.57cvss 9.8epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrative access and execute arbitrary code on the server. This affects FUXA through version 1.2.9 when…

  • CVE-2026-25505CriFeb 4, 2026
    risk 0.57cvss 9.8epss 0.01

    Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7.

  • CVE-2025-54947CriDec 12, 2025
    risk 0.57cvss 9.8epss 0.00

    In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely configuring the key.…

  • CVE-2025-5353HigJun 10, 2025
    risk 0.57cvss 8.8epss 0.00

    A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentials.

  • CVE-2025-22455HigJun 10, 2025
    risk 0.57cvss 8.8epss 0.00

    A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt stored SQL credentials.

  • CVE-2025-30206CriApr 15, 2025
    risk 0.57cvss 9.8epss 0.01

    Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service contains a hardcoded JWT secret in its default configuration, allowing attackers to generate valid JWT tokens and compromise the host machine. This security flaw…

  • CVE-2025-26340HigFeb 12, 2025
    risk 0.57cvss 8.8epss 0.01

    A CWE-321 "Use of Hard-coded Cryptographic Key" in the JWT signing in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to bypass the authentication via crafted HTTP requests.

  • CVE-2024-5722HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Logsign Unified SecOps Platform HTTP API Hard-coded Cryptographic Key Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Authentication is not required…

  • CVE-2024-6890HigAug 7, 2024
    risk 0.57cvss 8.8epss 0.01

    Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.

  • CVE-2024-33891HigApr 28, 2024
    risk 0.57cvss 8.8epss 0.01

    Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebService.asmx. This is related to a hardcoded key, the use of the integer 2 for the Admin user, and removal of the oauthExpirationId attribute.

  • CVE-2023-21705HigFeb 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Microsoft SQL Server Remote Code Execution Vulnerability

  • CVE-2023-20038HigJan 20, 2023
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing remote systems. This vulnerability is due to a static key…

  • CVE-2022-0664CriFeb 18, 2022
    risk 0.57cvss 9.8epss 0.02

    Use of Hard-coded Cryptographic Key in Go github.com/gravitl/netmaker prior to 0.8.5,0.9.4,0.10.0,0.10.1.

  • CVE-2021-27392HigApr 22, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in Siveillance Video Open Network Bridge (2020 R3), Siveillance Video Open Network Bridge (2020 R2), Siveillance Video Open Network Bridge (2020 R1), Siveillance Video Open Network Bridge (2019 R3), Siveillance Video Open Network Bridge (2019…

  • CVE-2026-33362HigMay 11, 2026
    risk 0.56cvss 8.6epss 0.00

    In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded and shared, including API signing material, password-transport keying, and service…

  • CVE-2025-13316HigNov 19, 2025
    risk 0.56cvss 8.1epss 0.03

    Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and gain…

  • CVE-2023-37291HigJul 21, 2023
    risk 0.56cvss 8.6epss 0.00

    Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data. This issue affects Vitals ESP:…

  • CVE-2026-34635HigAug 11, 2026
    risk 0.55cvss 8.4epss 0.00

    is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does…