VYPR

CWE-321

Use of Hard-coded Cryptographic Key

VariantDraftLikelihood: High

Description

The product uses a hard-coded, unchangeable cryptographic key.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (327)

page 6 of 17
  • CVE-2021-0266HigApr 22, 2021
    risk 0.53cvss 8.1epss 0.01

    The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issue affects: Juniper Networks Junos OS on cSRX Series: All…

  • CVE-2026-5426CriApr 16, 2026
    risk 0.52cvss 9.1epss 0.01

    Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks

  • CVE-2024-1631CriFeb 21, 2024
    risk 0.52cvss 9.1epss 0.01

    Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional param to provide a 32 byte seed value, which will then be used as the secret key. When no seed value is provided, it is expected that the library generates the…

  • CVE-2023-41137HigNov 9, 2023
    risk 0.52cvss 8.0epss 0.00

    Symmetric encryption used to protect messages between the AppsAnywhere server and client can be broken by reverse engineering the client and used to impersonate the AppsAnywhere server.

  • CVE-2022-34442HigJan 18, 2023
    risk 0.52cvss 8.0epss 0.00

    Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain LDAP…

  • CVE-2022-34441HigJan 11, 2023
    risk 0.52cvss 8.0epss 0.00

    Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin…

  • CVE-2020-7846HigFeb 24, 2021
    risk 0.52cvss 8.0epss 0.01

    Helpcom before v10.0 contains a file download and execution vulnerability caused by storing hardcoded cryptographic key. It finally leads to a file download and execution via access to crafted web page.

  • CVE-2026-66763HigAug 11, 2026
    risk 0.51cvss 7.9epss 0.00

    SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored…

  • CVE-2026-6787HigMay 6, 2026
    risk 0.51cvss 7.8epss 0.00

    Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Process.

  • CVE-2026-1442HigFeb 27, 2026
    risk 0.51cvss 7.8epss 0.00

    Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmware updates may be altered by an unauthorized user, and then trusted by a Unitree product, such as the Unitree…

  • CVE-2025-52601HigDec 26, 2025
    risk 0.51cvss 7.8epss 0.00

    Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a vulnerability in Device Manager that a hardcoded encryption key for sensitive information. An attacker can use key to decrypt…

  • CVE-2025-11781HigDec 2, 2025
    risk 0.51cvss 7.8epss 0.00

    Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the firmware image or memory dump) and create…

  • CVE-2020-25173HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.00

    An attacker with local network access can obtain a fixed cryptography key which may allow for further compromise of Reolink P2P cameras outside of local network access

  • CVE-2026-45041HigMay 28, 2026
    risk 0.50cvss epss 0.00

    RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, crates/appauth/src/token.rs ships a 2048-bit RSA private key as a string constant named TEST_PRIVATE_KEY and uses it in production via parse_license() to "verify" license tokens. Because the key…

  • CVE-2026-32324HigApr 17, 2026
    risk 0.50cvss 7.7epss 0.00

    Anviz CX7 Firmware is  vulnerable because the application embeds reusable certificate/key material, enabling decryption of MQTT traffic and potential interaction with device messaging channels at scale.

  • CVE-2025-46582HigOct 27, 2025
    risk 0.50cvss 7.7epss 0.00

    A private key disclosure vulnerability exists in ZTE's ZXMP M721 product. A low-privileged user can bypass authorization checks to view the device's communication private key, resulting in key exposure and impacting communication security.

  • CVE-2024-56429HigMay 21, 2025
    risk 0.50cvss 7.7epss 0.00

    itech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users to read or write to the database.

  • CVE-2024-31410HigMay 15, 2024
    risk 0.50cvss 7.7epss 0.00

    The devices which CyberPower PowerPanel manages use identical certificates based on a hard-coded cryptographic key. This can allow an attacker to impersonate any client in the system and send malicious data.

  • CVE-2017-5242HigJan 12, 2023
    risk 0.50cvss 7.7epss 0.00

    Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH host key should be generated the first time a virtual appliance boots.

  • CVE-2020-25234HigDec 14, 2020
    risk 0.50cvss 7.7epss 0.00

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3), LOGO! Soft Comfort (All versions < V8.3). The LOGO! program files generated and used by the affected components offer the possibility to save user-defined functions (UDF) in a…