VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 10 of 89
  • CVE-2025-11126CriSep 29, 2025
    risk 0.64cvss 9.8epss 0.01

    A security flaw has been discovered in Apeman ID71 218.53.203.117. This vulnerability affects unknown code of the file /system/www/system.ini. The manipulation results in hard-coded credentials. The attack may be performed from remote. The exploit has been released to the public…

  • CVE-2025-57602CriSep 22, 2025
    risk 0.64cvss 9.8epss 0.00

    Insufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined with the use of a shared, hardcoded SSH private key, allows remote attackers to authenticate to the cloud controller, gain interactive shell access, and pivot into other connected IoT…

  • CVE-2025-57601CriSep 22, 2025
    risk 0.64cvss 9.8epss 0.00

    AiKaan Cloud Controller uses a single hardcoded SSH private key and the username `proxyuser` for remote terminal access to all managed IoT/edge devices. When an administrator initiates "Open Remote Terminal" from the AiKaan dashboard, the controller sends this same static…

  • CVE-2025-34198CriSep 19, 2025
    risk 0.64cvss 9.8epss 0.01

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951 and Application prior to 20.0.2368 (VA and SaaS deployments) contain shared, hardcoded SSH host private keys in the appliance image. The same private host keys (RSA, ECDSA, and ED25519) are…

  • CVE-2025-8570CriSep 11, 2025
    risk 0.64cvss 9.8epss 0.01

    The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 3.0.1. This makes it possible for unauthenticated attackers to craft…

  • CVE-2025-35452CriSep 5, 2025
    risk 0.64cvss 9.8epss 0.01

    PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.

  • CVE-2025-35451CriSep 5, 2025
    risk 0.64cvss 9.8epss 0.01

    PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening on all interfaces. The passwords cannot be changed by the user, nor can the SSH or…

  • CVE-2025-8857CriAug 29, 2025
    risk 0.64cvss 9.8epss 0.01

    Clinic Image System developed by Changing contains hard-coded Credentials, allowing unauthenticated remote attackers to log into the system using administrator credentials embedded in the source code.

  • CVE-2025-43982CriAug 13, 2025
    risk 0.64cvss 9.8epss 0.00

    Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices enable the SSH service by default. There is a hidden hard-coded root account that cannot be disabled in the GUI.

  • CVE-2025-51536CriAug 4, 2025
    risk 0.64cvss 9.8epss 0.01

    Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.

  • CVE-2025-30125CriJul 28, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which creates an insecure-by-default condition. For users who change their passwords, it's limited to 8 characters. These short passwords…

  • CVE-2025-52376CriJul 15, 2025
    risk 0.64cvss 9.8epss 0.10

    An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, allowing an attacker to remotely enable the Telnet service without authentication, bypassing security controls. The Telnet server…

  • CVE-2025-7401CriJul 11, 2025
    risk 0.64cvss 9.8epss 0.01

    The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This…

  • CVE-2025-37103CriJul 8, 2025
    risk 0.64cvss 9.8epss 0.01

    Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.

  • CVE-2025-45813CriJul 2, 2025
    risk 0.64cvss 9.8epss 0.00

    ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.

  • CVE-2025-45784CriJun 18, 2025
    risk 0.64cvss 9.8epss 0.00

    D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may expose sensitive user credentials. An attacker with access to the firmware image can extract these credentials using static analysis tools such as strings or…

  • CVE-2025-46352CriMay 30, 2025
    risk 0.64cvss 9.8epss 0.01

    The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string in the binary responsible for running VNC. This password cannot be altered, allowing anyone with knowledge of it to gain remote access to the panel. Such …

  • CVE-2025-32985CriApr 25, 2025
    risk 0.64cvss 9.8epss 0.00

    NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.

  • CVE-2025-46274CriApr 24, 2025
    risk 0.64cvss 9.8epss 0.01

    UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create entries in the managed database.

  • CVE-2025-46273CriApr 24, 2025
    risk 0.64cvss 9.8epss 0.01

    UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges to all UNI-NMS managed devices.