VYPR

CWE-321

Use of Hard-coded Cryptographic Key

VariantDraftLikelihood: High

Description

The product uses a hard-coded, unchangeable cryptographic key.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (327)

page 5 of 17
  • CVE-2025-30239HigAug 10, 2026
    risk 0.55cvss epss 0.00

    In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to recover the keys and decrypt stored data. Successful exploitation may allow…

  • CVE-2026-11347HigJun 5, 2026
    risk 0.55cvss epss 0.00

    The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a limited ASCII charset to dynamically generate Initialization Vectors (IVs) for AES/CBC encryption, making known-plaintext attacks feasible. An attacker with…

  • CVE-2025-56577HigAug 29, 2025
    risk 0.55cvss 8.4epss 0.00

    An issue in Evope Core v.1.1.3.20 allows a local attacker to obtain sensitive information via the use of hard coded cryptographic keys.

  • CVE-2025-26476HigAug 4, 2025
    risk 0.55cvss 8.4epss 0.00

    Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

  • CVE-2022-34462HigJan 18, 2023
    risk 0.55cvss 8.4epss 0.00

    Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to login to the system to gain admin privileges.

  • CVE-2022-34440HigJan 11, 2023
    risk 0.55cvss 8.4epss 0.00

    Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin…

  • CVE-2025-40946HigMay 12, 2026
    risk 0.54cvss 8.3epss 0.00

    A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 105 TL3 (All versions), blueplanet 105 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 110 TL3 (All versions), blueplanet 125 NX3 M10 (All…

  • CVE-2025-30234HigMar 19, 2025
    risk 0.54cvss 8.3epss 0.00

    SmartOS, as used in Triton Data Center and other products, has static host SSH keys in the 60f76fd2-143f-4f57-819b-1ae32684e81b image (a Debian 12 LX zone image from 2024-07-26).

  • CVE-2026-18411HigAug 5, 2026
    risk 0.53cvss 8.1epss 0.00

    The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing…

  • CVE-2026-24218HigMay 20, 2026
    risk 0.53cvss 8.1epss 0.01

    NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all similarly provisioned systems enables host…

  • CVE-2015-10148HigApr 3, 2026
    risk 0.53cvss 8.2epss 0.00

    Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical default SSH and SSL keys that cannot be changed, allowing unauthenticated remote attackers to decrypt or intercept encrypted management communications.…

  • CVE-2026-0754HigMar 3, 2026
    risk 0.53cvss epss 0.00

    An embedded test key and certificate could be extracted from a Poly Voice device using specialized reverse engineering tools. This extracted certificate could be accepted by a SIP service provider if the service provider does not perform proper validation of the device…

  • CVE-2025-68948HigDec 27, 2025
    risk 0.53cvss 8.1epss 0.00

    SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardcoded cryptographic secret for its session store. This unsafe practice renders the session encryption ineffective. Since the…

  • CVE-2025-11899HigOct 17, 2025
    risk 0.53cvss 8.1epss 0.01

    Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information, thereby logging into the system as any user. Attacker must first obtain an user ID…

  • CVE-2024-54027HigMar 17, 2025
    risk 0.53cvss 8.2epss 0.00

    A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and below, version 3.1.5 and below, version 3.0.7 to 3.0.5 may allow a privileged attacker with super-admin…

  • CVE-2024-30407HigApr 12, 2024
    risk 0.53cvss 8.1epss 0.01

    The Use of a Hard-coded Cryptographic Key vulnerability in Juniper Networks Juniper Cloud Native Router (JCNR) and containerized routing Protocol Deamon (cRPD) products allows an attacker to perform Person-in-the-Middle (PitM) attacks which results in complete compromise of…

  • CVE-2023-40464HigDec 4, 2023
    risk 0.53cvss 8.1epss 0.00

    Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEManager server.

  • CVE-2023-0391HigMar 21, 2023
    risk 0.53cvss 8.1epss 0.01

    MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior was observed in version 2.2.0. There has been no indication from the vendor this has been…

  • CVE-2021-43587HigDec 21, 2021
    risk 0.53cvss 8.2epss 0.00

    Dell PowerPath Management Appliance, versions 3.2, 3.1, 3.0 P01, 3.0, and 2.6, use hard-coded cryptographic key. A local high-privileged malicious user may potentially exploit this vulnerability to gain access to secrets and elevate to gain higher privileges.

  • CVE-2021-38461HigOct 22, 2021
    risk 0.53cvss 8.2epss 0.01

    The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted from binaries.